Skip to content
Apache ZooKeeperGHSA-ccqf-c5hq-77mp

Missing Authorization in Apache ZooKeeper

High7.5CVE-2018-8012 · Published May 13, 2022 · updated Nov 8, 2023

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.zookeeper:zookeeper
Maven
< 3.4.103.4.10
>= 3.5.0-alpha, < 3.5.4-beta3.5.4-beta
Details and references

More Apache ZooKeeper advisories

All Apache ZooKeeper
Advisory
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Medium4.3Sep 24, 2025
Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
HighNov 7, 2024
Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
Medium5.3Mar 15, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
Critical9.1Oct 11, 2023
Uncontrolled Resource Consumption in Apache ZooKeeper
High7.5May 13, 2022
Access control bypass in Apache ZooKeeper
Medium5.9May 29, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.