Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-8012

Опубликовано: 22 мая 2018
Источник: redhat
CVSS3: 7.4

Описание

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

Отчет

Zookeeper is not designed to run as a publicly available service and it always needs to be deployed and operated in a secured environment. As a result it is assumed that no zookeeper ports are available publically, so with this assumption JBoss Fuse is not affected by this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6zookeeperNot affected
Red Hat Fuse 7zookeeperNot affected
Red Hat JBoss A-MQ 6zookeeperWill not fix
Red Hat JBoss BRMS 6zookeeperNot affected
Red Hat JBoss Data Virtualization 6zookeeperNot affected
Red Hat JBoss Fuse 6zookeeperWill not fix
Red Hat JBoss Fuse Integration Service 2zookeeperNot affected
Red Hat JBoss Fuse Service Works 6zookeeperNot affected
Red Hat OpenShift Application RuntimeszookeeperNot affected
streams for Apache KafkazookeeperNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1581542zookeeper: No authentication or authorization is enforced when a server joins a quorum

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

CVSS3: 7.5
nvd
около 7 лет назад

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

CVSS3: 7.5
debian
около 7 лет назад

No authentication/authorization is enforced when a server attempts to ...

CVSS3: 7.5
github
около 3 лет назад

Missing Authorization in Apache ZooKeeper

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость централизованной службы для поддержки информации о конфигурации, именования, обеспечения распределенной синхронизации и предоставления групповых служб Apache ZooKeeper, позволяющая нарушителю записать произвольные файлы в операционной системе уязвимого устройства

7.4 High

CVSS3