Description
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.
Remediation
References
http://mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/%3CCA+RK=_CFiTfQ2d0V+kuJx_y5izmYccaKjXaJ3V72KK7tbOhbkg%40mail.gmail.com%3E
http://www.securitytracker.com/id/1034365
http://www-01.ibm.com/support/docview.wss?uid=swg21969546
https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
Related Vulnerabilities
CVE-2018-3827 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2023-26475 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-35925 Vulnerability in maven package com.fastasyncworldedit:fastasyncworldedit-core
CVE-2017-9791 Vulnerability in maven package org.apache.struts:struts2-struts1-plugin
CVE-2021-38296 Vulnerability in maven package org.apache.spark:spark-core