5
CVSSv2

CVE-2018-8012

Published: 21/05/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper prior to 3.4.10, and 3.5.0-alpha up to and including 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache zookeeper 3.5.3

apache zookeeper 3.5.0

apache zookeeper

debian debian linux 8.0

debian debian linux 9.0

oracle goldengate stream analytics

Vendor Advisories

Debian Bug report logs - #899332 CVE-2018-8012: Apache ZooKeeper Quorum Peer mutual authentication Package: zookeeper; Maintainer for zookeeper is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for zookeeper is src:zookeeper (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg ...
Debian Bug report logs - #929283 zookeeper: CVE-2019-0201: information disclosure vulnerability Package: src:zookeeper; Maintainer for src:zookeeper is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 20 May 2019 20:06:01 UTC Seve ...
It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum This update backports authentication support Additional configuration steps are needed, please see cwikiapacheorg/confluence/display/ZOOKEEPER/Server-Server+mut ...
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3410, and 350-alpha through 353-beta As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader ...