Back

HIGH

HBase: insecure ACLs in ZooKeeper

Published Dec 21, 2015

Description

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 21, 2015
Updated Aug 6, 2024
Reserved Feb 17, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 25, 2015
GHSA-P8XR-4V2C-RVGP