← Back

CVE-2019-0201

nvd nist
Published: May 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.

Affected (30)

Products: Apache: Activemq, Drill, Zookeeper · Debian: Debian Linux · Redhat: Fuse · +2 more
Show all products
3 products
Activemq
Drill
Zookeeper
1 product
Debian Linux
1 product
Fuse
3 products
Goldengate Stream Analytics
Siebel Core Server Framework
Timesten In Memory Database
2 products
Hci Bootstrap Os
Element Software
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.15.9
Version 1.16.0
Apache
From 1.0.0 to 3.4.13
Version 3.5.0
Version 3.5.0 alpha
Version 3.5.0 rc0
Version 3.5.1
Version 3.5.1 alpha
Version 3.5.1 rc0
Version 3.5.1 rc1
Version 3.5.1 rc2
Version 3.5.1 rc3
Version 3.5.1 rc4
Version 3.5.2
Version 3.5.2 alpha
Version 3.5.2 rc0
Version 3.5.2 rc1
Version 3.5.3
Version 3.5.3 beta
Version 3.5.3 rc0
Version 3.5.3 rc1
Version 3.5.4 beta
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 19.1.0.0.1
Up to 21.5
Before 18.1.3.1.0
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (40)

Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Issue TrackingPatchVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.