No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2018-05-21 12:29
Updated : 2021-09-14 05:13
NVD link : CVE-2018-8012
Mitre link : CVE-2018-8012
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
debian
- debian_linux
oracle
- goldengate_stream_analytics
apache
- zookeeper