← back
CVE-2018-8012

CVE-2018-8012

EPSS 8.7%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 8.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
21 May 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →