扫描漏洞详情如下:
目录
1.漏洞详情
漏洞名称 | Apache Zookeeper 授权问题漏洞(CVE-2019-0201) |
---|---|
发现日期 | 2019-05-23 |
CVSS评分 | 5.9 |
漏洞描述 | Apache Zookeeper是美国阿帕奇(Apache)软件基金会的一个软件项目,它能够为大型分布式计算提供开源的分布式配置服务、同步服务和命名注册等功能。 Apache ZooKeeper 1.0.0版本至3.4.13版本和3.5.0-alpha版本至3.5.4-beta版本中存在授权问题漏洞。该漏洞源于网络系统或产品中缺少身份验证措施或身份验证强度不足。 |
解决方案 | 厂商补丁: 目前厂商已发布升级补丁以修复漏洞,补丁获取链接: https://zookeeper.apache.org/security.html#CVE-2019-0201 |
解决方式:
只授权集群内部访问
zkCli.sh 进入zk后执行如下命令:
setAcl / ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /zookeeper ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /cluster ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /controller_epoch ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /controller ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /brokers ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /feature ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /admin ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /isr_change_notification ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /consumers ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /log_dir_event_notification ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /latest_producer_id_block ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa
setAcl /config ip:192.168.0.13:cdrwa,ip:192.168.0.14:cdrwa,ip:192.168.0.15:cdrwa,ip:127.0.0.1:cdrwa