No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "3.4.10"
},
{
"introduced": "3.5.0"
},
{
"last_affected": "3.5.3"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.5.0-alpha"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.5.3-beta"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "19.1.0.0.1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8012.json"