UBUNTU-CVE-2018-8012
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-8012
UBUNTU-CVE-2018-8012
Summary:
Details: No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
References: https://ubuntu.com/security/CVE-2018-8012, https://issues.apache.org/jira/browse/ZOOKEEPER-1045, http://www.openwall.com/lists/oss-security/2018/05/21/6, https://cwiki.apache.org/confluence/display/ZOOKEEPER/Server-Server+mutual+authentication, https://issues.apache.org/jira/secure/attachment/12840904/ZOOKEEPER-1045-br-3-4.patch, https://lists.apache.org/thread.html/c75147028c1c79bdebd4f8fa5db2b77da85de2b05ecc0d54d708b393@%3Cdev.zookeeper.apache.org%3E, https://ubuntu.com/security/notices/USN-4789-1, https://www.cve.org/CVERecord?id=CVE-2018-8012
Affected packages
Package
Name: zookeeper
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu0.1~esm3?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
