Description
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.
Remediation
References
http://mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/%3CCA+RK=_CFiTfQ2d0V+kuJx_y5izmYccaKjXaJ3V72KK7tbOhbkg%40mail.gmail.com%3E
http://www.securitytracker.com/id/1034365
http://www-01.ibm.com/support/docview.wss?uid=swg21969546
https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
Related Vulnerabilities
CVE-2015-0254 Vulnerability in maven package org.apache.taglibs:taglibs-standard-impl
CVE-2021-21380 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ratings-api
CVE-2019-10350 Vulnerability in maven package org.jenkins-ci.plugins:port-allocator
CVE-2014-3623 Vulnerability in maven package org.apache.ws.security:wss4j
CVE-2019-1003009 Vulnerability in maven package rg.jenkins-ci.plugins:active-directory