CVE-2018-8012 – org.apache.zookeeper:zookeeper
Package
Manager: maven
Name: org.apache.zookeeper:zookeeper
Vulnerable Version: >=0 <3.4.10 || >=3.5.0-alpha <3.5.4-beta
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.0113 pctl0.775
Details
Missing Authorization in Apache ZooKeeper No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Metadata
Created: 2022-05-13T01:05:57Z
Modified: 2022-06-29T19:03:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-ccqf-c5hq-77mp/GHSA-ccqf-c5hq-77mp.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-ccqf-c5hq-77mp
Finding: F039
Auto approve: 1