Executive Summary

Informations
Name CVE-2023-44981 First vendor Publication 2023-10-11
Vendor Cve Last vendor Modification 2025-04-23

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Overall CVSS Score 9.1
Base Score 9.1 Environmental Score 9.1
impact SubScore 5.2 Temporal Score 9.1
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like 'eve@EXAMPLE.COM', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default.

Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue.

Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue.

See the documentation for more details on correct cluster administration.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44981

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-639 Access Control Bypass Through User-Controlled Key

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 35
Os 3

Sources (Detail)

http://www.openwall.com/lists/oss-security/2023/10/11/4
https://lists.apache.org/thread/wf0yrk84dg1942z1o74kd8nycg6pgm5b
https://lists.debian.org/debian-lts-announce/2023/10/msg00029.html
https://security.netapp.com/advisory/ntap-20240621-0007/
https://www.debian.org/security/2023/dsa-5544
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
Date Informations
2025-07-01 13:14:48
  • Multiple Updates
2025-05-27 02:23:59
  • Multiple Updates
2025-02-13 21:21:37
  • Multiple Updates
2024-11-28 14:30:04
  • Multiple Updates
2024-06-22 00:27:36
  • Multiple Updates
2024-02-22 00:27:46
  • Multiple Updates
2023-11-01 13:27:40
  • Multiple Updates
2023-10-21 21:27:39
  • Multiple Updates
2023-10-19 00:27:31
  • Multiple Updates
2023-10-11 21:27:20
  • Multiple Updates
2023-10-11 17:27:19
  • First insertion