CVE-2018-8012

HIGH

Apache ZooKeeper <3.4.10, <3.5.0-alpha-<3.5.3-beta - DoS

Title source: llm
STIX 2.1

Description

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

References (12)

Core 12
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4214
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040948
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104253
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html

Scores

CVSS v3 7.5
EPSS 0.0137
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-862
Status published
Products (7)
apache/zookeeper 3.5.0 alpha
apache/zookeeper 3.5.3 beta
apache/zookeeper < 3.4.10
debian/debian_linux 8.0
debian/debian_linux 9.0
oracle/goldengate_stream_analytics < 19.1.0.0.1
org.apache.zookeeper/zookeeper 0 - 3.4.10Maven
Published May 21, 2018
Tracked Since Feb 18, 2026