Back

HIGH

zookeeper: No authentication or authorization is enforced when a server joins a quorum

Published May 21, 2018

Description

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

Affected products

Remediation

Red Hat statement

Zookeeper is not designed to run as a publicly available service and it always needs to be deployed and operated in a secured environment. As a result it is assumed that no zookeeper ports are available publically, so with this assumption JBoss Fuse is not affected by this issue.

Metrics

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published May 21, 2018
Updated Sep 17, 2024
Reserved Mar 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 22, 2018
GHSA-CCQF-C5HQ-77MP