Severity
7.5HIGH
EPSS
1.4%
top 19.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateMay 13

Description

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDapache/zookeeper3.5.03.5.3+3
Mavenorg.apache.zookeeper:zookeeper3.5.0-alpha3.5.4-beta+1
CVEListV5apache_software_foundation/apache_zookeeperApache ZooKeeper prior to 3.4.10, Apache ZooKeeper 3.5.0-alpha through 3.5.3-beta
Debianzookeeper< 3.4.10-2+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

5
OSV
Missing Authorization in Apache ZooKeeper2022-05-13
GHSA
Missing Authorization in Apache ZooKeeper2022-05-13
OSV
zookeeper vulnerabilities2021-03-15
OSV
CVE-2018-8012: No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 32018-05-21
CVEList
CVE-2018-8012: No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 32018-05-21

📋Vendor Advisories

3
Ubuntu
Apache ZooKeeper vulnerabilities2021-03-15
Red Hat
zookeeper: No authentication or authorization is enforced when a server joins a quorum2018-05-22
Debian
CVE-2018-8012: zookeeper - No authentication/authorization is enforced when a server attempts to join a quo...2018

💬Community

2
Bugzilla
CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum2018-05-23
Bugzilla
CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum [fedora-all]2018-05-23
CVE-2018-8012 (HIGH CVSS 7.5) | No authentication/authorization is | cvebase.io