CVE-2018-8012
21.05.2018, 19:29
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.Enginsight
Vendor | Product | Version |
---|---|---|
apache | zookeeper | 𝑥 < 3.4.10 |
apache | zookeeper | 3.5.0 ≤ 𝑥 ≤ 3.5.3 |
apache | zookeeper | 3.5.0:alpha |
apache | zookeeper | 3.5.3:beta |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
oracle | goldengate_stream_analytics | 𝑥 < 19.1.0.0.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
zookeeper |
|
Common Weakness Enumeration
References