Improper authentication in ZooKeeper - CVE-2018-8012

 

Improper authentication in ZooKeeper - CVE-2018-8012

Published: May 22, 2018


Vulnerability identifier: #VU12913
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8012
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and write arbitrary files on the target system.

The weakness exists due to missing authentication to join a quorum. A remote attacker can bypass authentication, join the cluster and propagate changes to the cluster leader.

Affected software

ZooKeeper
Debian Linux
IBM PureData System for Operational Analytics
IBM SPSS Analytic Server
Planning Analytics Local
IBM Security Guardium
StreamSets Data Collector

How to mitigate CVE-2018-8012

Update to version 3.4.10 or 3.5.4-beta.

Planning Analytics Local - update to 2.0.1
StreamSets Data Collector - update to 7.0.0

External References

Related Security Bulletins