Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Damien Diederen discovered that SASL quorum peer authentication within Zookeeper, a service for maintaining configuration information, was insufficiently enforced in some configurations. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5544-1
It was discovered that there was a potential authorisation bypass vulnerability in Apache Zookeeper, a co-ordination service for reliable distributed applications. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3624-1
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openstack-monasca-agent, spark, spark-kit, zookeeper ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0133-1 Rating: important References: #1193662 Cross-References: CVE-2021-4104 CVSS scores: CVE-2021-4104 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud 9 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openstack-monasca-agent, spark, spark-kit, zookeeper fixes the following issues: - CVE-2021-4104: Remove JMSAppender from log4j jars (bsc#1193662) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-133=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-133=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (noarch): openstack-monasca-agent-2.8.2~dev5-3.15.1 python-monasca-agent-2.8.2~dev5-3.15.1 spark-2.2.3-5.6.1 zookeeper-server-3.4.13-3.9.1 - SUSE OpenStack Cloud 9 (noarch): openstack-monasca-agent-2.8.2~dev5-3.15.1 python-monasca-agent-2.8.2~dev5-3.15.1 spark-2.2.3-5.6.1 venv-openstack-monasca-x86_64-2.7.1~dev10-3.29.1 zookeeper-server-3.4.13-3.9.1 References: https://www.suse.com/security/cve/CVE-2021-4104.html https://bugzilla.suse.com/1193662 . SUSE Security Bulletin: Mitigating significant vulnerabilities in openstack-monasca-collector and associated components.. SUSEOpenStack Security, Security Patch, OpenStack Updates. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openstack-monasca-agent, spark, spark-kit, zookeeper ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0126-1 Rating: important References: #1193662 Cross-References: CVE-2021-4104 CVSS scores: CVE-2021-4104 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openstack-monasca-agent, spark, spark-kit, zookeeper fixes the following issues: - CVE-2021-4104: Remove JMSAppender from log4j jars (bsc#1193662) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-126=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-126=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-126=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): openstack-monasca-agent-2.2.6~dev4-3.24.1 python-monasca-agent-2.2.6~dev4-3.24.1 spark-1.6.3-8.9.2 zookeeper-server-3.4.10-3.12.1 - SUSE OpenStack Cloud 8 (noarch): openstack-monasca-agent-2.2.6~dev4-3.24.1 python-monasca-agent-2.2.6~dev4-3.24.1 spark-1.6.3-8.9.2 venv-openstack-monasca-x86_64-2.2.2~dev1-11.37.1 zookeeper-server-3.4.10-3.12.1 - HPE Helion Openstack 8 (noarch): openstack-monasca-agent-2.2.6~dev4-3.24.1 python-monasca-agent-2.2.6~dev4-3.24.1 spark-1.6.3-8.9.2 venv-openstack-monasca-x86_64-2.2.2~dev1-11.37.1 zookeeper-server-3.4.10-3.12.1 References: https://www.suse.com/security/cve/CVE-2021-4104.html https://bugzilla.suse.com/1193662 . SUSE has issued a critical security patch that resolves an issue found in openstack-monasca-agent as well as various other modules.. SUSE Security Update, OpenStack Patch, Log4j Issue, Spark Security. . Severity: Important. LinuxSecurity.com Team
Harrison Neil discovered that the getACL() command in Zookeeper, a service for maintaining configuration information, did not validate permissions, which could result in information disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4461-1
It was discovered that there was an information disclosure vulnerability in zookeeper, a distributed co-ordination server. Users who were not authorised to read data were able to view the access control list. . Package : zookeeper Version : 3.4.9-3+deb8u2 CVE ID : CVE-2019-0201 Debian Bug : #929283 It was discovered that there was an information disclosure vulnerability in zookeeper, a distributed co-ordination server. Users who were not authorised to read data were able to view the access control list. For Debian 8 "Jessie", this issue has been fixed in zookeeper version 3.4.9-3+deb8u2. We recommend that you upgrade your zookeeper packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4214-1
It was discovered that Zookeeper, a service for maintaining configuration information, didn't restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption. . Hash: SHA512 Package : zookeeper Version : 3.4.5+dfsg-2+deb7u1 CVE ID : CVE-2017-5637 Debian Bug : 863811 It was discovered that Zookeeper, a service for maintaining configuration information, didn't restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption. This update disables those two commands by default. The new configuration option "4lw.commands.whitelist" can be used to whitelist commands selectively (and the full set of commands can be restored with '*') For Debian 7 "Wheezy", these problems have been fixed in version 3.4.5+dfsg-2+deb7u1. We recommend that you upgrade your zookeeper packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The configuration adjustment in the database management utility limits command access to mitigate risks of service unavailability and CPU overload scenarios.. Zookeeper Update, Debian Security, Service Hardening. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.