Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits: 2307b820 by Bastien Roucariès at 2024-04-15T08:15:12+00:00 CVE-2024-23944/zookeeper There is indeed a triggerWatch in 3.4, and it arguably leaks *some* information. E.g., super> create /foo X world:anyone: noauth> ls /foo Insufficient permission : /foo noauth> stat -w /foo/bar Node does not exist: /foo/bar super> create /foo/bar 42 world:anyone: noauth> WATCHER:: WatchedEvent state:SyncConnected type:NodeCreated path:/foo/bar zxid: -1 However it seems that it is not possible for watches to trigger for nodes whose names are not known in advance. That is CVE-2024-23944 Thanks to Damien Diederen - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -9378,6 +9378,9 @@ CVE-2024-23944 (Information disclosure in persistent watchers handling in Apache NOTE: https://issues.apache.org/jira/browse/ZOOKEEPER-4799 NOTE: Fixed by: https://github.com/apache/zookeeper/commit/65b91d2d9a56157285c2a86b106e67c26520b01d (release-3.8.4-0) NOTE: Fixed by: https://github.com/apache/zookeeper/commit/daf7cfd04005cff1a4f7cab5ab13d41db88d0cd8 (release-3.9.2-0) + NOTE: Persistent (and p-recursive) watches were introduced by ZOOKEEPER-1416, which only exists in 3.6+. + NOTE: See https://issues.apache.org/jira/browse/ZOOKEEPER-1416 + NOTE: However, classical watches are used (<< 3.6), it seems that to trigger for nodes whose names are not known in advance is not possible. Nevertheless classical watch leaks some information CVE-2024-2746 NOT-FOR-US: dnf5daemon-server CVE-2024-1930 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2307b820ca2c6aaae182e74aa344239c1e7a3499 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2307b820ca2c6aaae182e74aa344239c1e7a3499 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits