CVE-2018-8012
published 2018-05-21CVE-2018-8012: No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
8.72%
94.6th percentile
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | zookeeper | < 3.4.10 | 3.4.10 |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | >= 0 < 3.4.10-2 | 3.4.10-2 |
| apache | zookeeper | >= 0 < 3.4.10-2 | 3.4.10-2 |
| apache | zookeeper | >= 0 < 3.4.10-2 | 3.4.10-2 |
| apache | zookeeper | >= 0 < 3.4.10-2 | 3.4.10-2 |
| apache | zookeeper | >= 0 < 3.4.5+dfsg-1ubuntu0.1~esm1 | 3.4.5+dfsg-1ubuntu0.1~esm1 |
| apache | zookeeper | >= 0 < 3.4.8-1ubuntu0.1~esm1 | 3.4.8-1ubuntu0.1~esm1 |
| apache | zookeeper | 3.5.0 – 3.5.3 | — |
| apache_software_foundation | apache_zookeeper | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | zookeeper | < zookeeper 3.4.10-2 (bookworm) | zookeeper 3.4.10-2 (bookworm) |
| oracle | goldengate_stream_analytics | < 19.1.0.0.1 | 19.1.0.0.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Missing Authorization in Apache ZooKeeper
osv·2022-05-13
CVE-2018-8012 [HIGH] Missing Authorization in Apache ZooKeeper
Missing Authorization in Apache ZooKeeper
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
GHSA
Missing Authorization in Apache ZooKeeper
ghsa·2022-05-13
CVE-2018-8012 [HIGH] CWE-862 Missing Authorization in Apache ZooKeeper
Missing Authorization in Apache ZooKeeper
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
OSV
zookeeper vulnerabilities
osv·2021-03-15·CVSS 8.1
CVE-2016-5017 [HIGH] zookeeper vulnerabilities
zookeeper vulnerabilities
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2018-8012)
OSV
CVE-2018-8012: No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3
osv·2018-05-21·CVSS 7.5
CVE-2018-8012 [HIGH] CVE-2018-8012: No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Ubuntu
Apache ZooKeeper vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 8.1
CVE-2017-5637 [HIGH] Apache ZooKeeper vulnerabilities
Title: Apache ZooKeeper vulnerabilities
Summary: Several security issues were fixed in Apache ZooKeeper.
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2018-8012)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
zookeeper: No authentication or authorization is enforced when a server joins a quorum
vendor_redhat·2018-05-22·CVSS 7.5
CVE-2018-8012 [HIGH] CWE-306 zookeeper: No authentication or authorization is enforced when a server joins a quorum
zookeeper: No authentication or authorization is enforced when a server joins a quorum
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Statement: Zookeeper is not designed to run as a publicly available service and it always needs to be deployed and operated in a secured environment. As a result it is assumed that no zookeeper ports are available publically, so with this assumption JBoss Fuse is not affected by this issue.
Package: zookeeper (Red Hat BPM Suite 6) - Not affected
Package: zookeeper (Red Hat Fuse 7) - Not affected
Package: zookeeper (Red Hat JBoss A-MQ
Debian
CVE-2018-8012: zookeeper - No authentication/authorization is enforced when a server attempts to join a quo...
vendor_debian·2018·CVSS 7.5
CVE-2018-8012 [HIGH] CVE-2018-8012: zookeeper - No authentication/authorization is enforced when a server attempts to join a quo...
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Scope: local
bookworm: resolved (fixed in 3.4.10-2)
bullseye: resolved (fixed in 3.4.10-2)
forky: resolved (fixed in 3.4.10-2)
sid: resolved (fixed in 3.4.10-2)
trixie: resolved (fixed in 3.4.10-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum
bugzilla·2018-05-23·CVSS 7.5
CVE-2018-8012 [HIGH] CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum
CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum
Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta does not enforce any authentication/authorization when a server attempts to join a quorum. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
External References:
http://openwall.com/lists/oss-security/2018/05/21/6
https://cwiki.apache.org/confluence/display/ZOOKEEPER/Server-Server+mutual+authentication
https://issues.apache.org/jira/browse/ZOOKEEPER-1045
Discussion:
Created zookeeper tracking bugs for this issue:
Affects: fedora-all [bug 1581543]
---
Zookeeper is not a supported feature of VertX according to:
https://access.redhat.com/documentation/en-
Bugzilla
CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum [fedora-all]
bugzilla·2018-05-23·CVSS 7.5
CVE-2018-8012 [HIGH] CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum [fedora-all]
CVE-2018-8012 zookeeper: No authentication or authorization is enforced when a server joins a quorum [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
http://www.securityfocus.com/bid/104253http://www.securitytracker.com/id/1040948https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/c75147028c1c79bdebd4f8fa5db2b77da85de2b05ecc0d54d708b393%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r73daf1fc5d85677d9a854707e1908d14e174b7bbb0c603709c0ab33f%40%3Coak-commits.jackrabbit.apache.org%3Ehttps://lists.apache.org/thread.html/r8f0d920805af93033c488af89104e2d682662bacfb8406db865d5e14%40%3Cdev.jackrabbit.apache.org%3Ehttps://lists.apache.org/thread.html/rc5bc4ddb0deabf8cfb69378cecee56fcdc76929bea9e6373cb863870%40%3Cdev.jackrabbit.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/re3a4048e9515d4afea416df907a612ed384a16c57cf99e97ee4a12f2%40%3Cdev.jackrabbit.apache.org%3Ehttps://www.debian.org/security/2018/dsa-4214https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.securityfocus.com/bid/104253http://www.securitytracker.com/id/1040948https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/c75147028c1c79bdebd4f8fa5db2b77da85de2b05ecc0d54d708b393%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r73daf1fc5d85677d9a854707e1908d14e174b7bbb0c603709c0ab33f%40%3Coak-commits.jackrabbit.apache.org%3Ehttps://lists.apache.org/thread.html/r8f0d920805af93033c488af89104e2d682662bacfb8406db865d5e14%40%3Cdev.jackrabbit.apache.org%3Ehttps://lists.apache.org/thread.html/rc5bc4ddb0deabf8cfb69378cecee56fcdc76929bea9e6373cb863870%40%3Cdev.jackrabbit.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/re3a4048e9515d4afea416df907a612ed384a16c57cf99e97ee4a12f2%40%3Cdev.jackrabbit.apache.org%3Ehttps://www.debian.org/security/2018/dsa-4214https://www.oracle.com/security-alerts/cpujul2020.html
2018-05-21
Published