CVE-2018-8012 PUBLISHED

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

EPSS 1.37% · 80.1th percentile

Risk Scores

EPSS Score
1.37%
80.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSzookeeper3.4.8-1, 0, 3.4.6-8
Ubuntu:Pro:14.04:LTSzookeeper0, 3.4.5+dfsg-1, 3.4.5+dfsg-1ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →