No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zookeeper | Feb 19, 2019 | May 21, 2018 |
| Ubuntu | — | Upgrade libzookeeper-st2 (Ubuntu Pro)Upgrade libzookeeper-mt2 (Ubuntu Pro)Upgrade zookeeperd (Ubuntu Pro)Upgrade zookeeper-bin (Ubuntu Pro)Upgrade python-zookeeper (Ubuntu Pro)Upgrade libzookeeper-java (Ubuntu Pro)Upgrade libzookeeper2 (Ubuntu Pro)Upgrade zookeeper (Ubuntu Pro) | Mar 22, 2023 | May 21, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub