Bastien Roucariès pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2307b820 by Bastien Roucariès at 2024-04-15T08:15:12+00:00
CVE-2024-23944/zookeeper

There is indeed a triggerWatch in 3.4, and it arguably leaks *some*
information.  E.g.,

super> create /foo X world:anyone:

noauth> ls /foo
Insufficient permission : /foo

noauth> stat -w /foo/bar
Node does not exist: /foo/bar

super> create /foo/bar 42 world:anyone:

noauth>
WATCHER::
WatchedEvent state:SyncConnected type:NodeCreated path:/foo/bar zxid: -1

However it seems that it is not possible for watches to trigger for nodes whose 
names are not
known in advance. That is CVE-2024-23944

Thanks to Damien Diederen

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9378,6 +9378,9 @@ CVE-2024-23944 (Information disclosure in persistent 
watchers handling in Apache
        NOTE: https://issues.apache.org/jira/browse/ZOOKEEPER-4799
        NOTE: Fixed by: 
https://github.com/apache/zookeeper/commit/65b91d2d9a56157285c2a86b106e67c26520b01d
 (release-3.8.4-0)
        NOTE: Fixed by: 
https://github.com/apache/zookeeper/commit/daf7cfd04005cff1a4f7cab5ab13d41db88d0cd8
 (release-3.9.2-0)
+       NOTE: Persistent (and p-recursive) watches were introduced by 
ZOOKEEPER-1416, which only exists in 3.6+.
+       NOTE: See https://issues.apache.org/jira/browse/ZOOKEEPER-1416
+       NOTE: However, classical watches are used (<< 3.6), it seems that to 
trigger for nodes whose names are not known in advance is not possible. 
Nevertheless classical watch leaks some information
 CVE-2024-2746
        NOT-FOR-US: dnf5daemon-server
 CVE-2024-1930



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2307b820ca2c6aaae182e74aa344239c1e7a3499

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2307b820ca2c6aaae182e74aa344239c1e7a3499
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to