You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
CVE-2018-8012 - High Severity Vulnerability
Vulnerable Library - zookeeper-3.4.9.jar
null
path: null
Dependency Hierarchy:
Vulnerability Details
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Publish Date: 2018-05-21
URL: CVE-2018-8012
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: http://www.securitytracker.com/id/1040948
Fix Resolution: The vendor has issued a fix that allows Quorum Peer mutual authentication to be enabled (3.4.10).
The vendor advisory is available at:
http://zookeeper.apache.org/security.html#CVE-2018-8012
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: