Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0201


An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.


Published

2019-05-23T14:29:07.517

Last Modified

2024-11-21T04:16:28.487

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache activemq 5.15.9 Yes
Application apache drill 1.16.0 Yes
Application apache zookeeper ≤ 3.4.13 Yes
Application apache zookeeper 3.5.0 Yes
Application apache zookeeper 3.5.0 Yes
Application apache zookeeper 3.5.0 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.1 Yes
Application apache zookeeper 3.5.2 Yes
Application apache zookeeper 3.5.2 Yes
Application apache zookeeper 3.5.2 Yes
Application apache zookeeper 3.5.2 Yes
Application apache zookeeper 3.5.3 Yes
Application apache zookeeper 3.5.3 Yes
Application apache zookeeper 3.5.3 Yes
Application apache zookeeper 3.5.3 Yes
Application apache zookeeper 3.5.4 Yes
Operating System debian debian_linux 8.0 Yes
Operating System debian debian_linux 9.0 Yes
Application redhat fuse 1.0.0 Yes
Application oracle goldengate_stream_analytics < 19.1.0.0.1 Yes
Application oracle siebel_core_-_server_framework ≤ 21.5 Yes
Application oracle timesten_in-memory_database < 18.1.3.1.0 Yes
Operating System netapp hci_bootstrap_os - Yes
Hardware netapp hci_compute_node - No
Application netapp element_software - Yes

References