First published: Wed Oct 11 2023(Updated: )
Apache ZooKeeper could allow a remote attacker to bypass security restrictions, caused by a flaw when SASL Quorum Peer authentication is enabled. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass authorization and allow arbitrary endpoints to join the cluster and begin propagating counterfeit changes.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ZooKeeper | <3.7.2 | |
Apache ZooKeeper | >=3.8.0<3.8.3 | |
Apache ZooKeeper | =3.9.0 | |
maven/org.apache.zookeeper:zookeeper | >=3.9.0<3.9.1 | 3.9.1 |
maven/org.apache.zookeeper:zookeeper | >=3.8.0<3.8.3 | 3.8.3 |
maven/org.apache.zookeeper:zookeeper | <3.7.2 | 3.7.2 |
ubuntu/zookeeper | <3.4.13-3ubuntu0.1~ | 3.4.13-3ubuntu0.1~ |
ubuntu/zookeeper | <3.4.13-5ubuntu0.1 | 3.4.13-5ubuntu0.1 |
ubuntu/zookeeper | <3.4.13-6ubuntu4.1 | 3.4.13-6ubuntu4.1 |
ubuntu/zookeeper | <3.8.0-10ubuntu0.1 | 3.8.0-10ubuntu0.1 |
ubuntu/zookeeper | <3.7.2<3.8.3<3.9.1 | 3.7.2 3.8.3 3.9.1 |
ubuntu/zookeeper | <3.8.0-11ubuntu0.1 | 3.8.0-11ubuntu0.1 |
debian/zookeeper | <=3.4.13-2 | 3.4.13-2+deb10u1 3.4.13-6+deb11u1 3.8.0-11+deb12u1 3.9.1-1 |
redhat/zookeeper | <3.9.1 | 3.9.1 |
redhat/zookeeper | <3.8.3 | 3.8.3 |
redhat/zookeeper | <3.7.2 | 3.7.2 |
IBM Cognos Analytics | <=12.0-12.0.2 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP2 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
<3.7.2 | ||
>=3.8.0<3.8.3 | ||
=3.9.0 | ||
=10.0 | ||
=11.0 | ||
=12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44981 is a vulnerability in Apache ZooKeeper that allows authorization bypass through user-controlled key.
The severity of CVE-2023-44981 is critical with a CVSS score of 9.1.
CVE-2023-44981 affects Apache ZooKeeper by enabling an authorization bypass in SASL Quorum Peer Authentication.
CVE-2023-44981 affects Apache ZooKeeper versions 3.9.0 to 3.9.1, 3.8.0 to 3.8.3, and 3.7.2.
To fix CVE-2023-44981, update Apache ZooKeeper to version 3.9.1, 3.8.3, or 3.7.2.