CVE-2019-0201
published 2019-05-23CVE-2019-0201: An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves…
PriorityP340medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
9.63%
95.0th percentile
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | — | — |
| apache | drill | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | >= 0 < 3.4.13-2 | 3.4.13-2 |
| apache | zookeeper | >= 0 < 3.4.13-2 | 3.4.13-2 |
| apache | zookeeper | >= 0 < 3.4.13-2 | 3.4.13-2 |
| apache | zookeeper | >= 0 < 3.4.13-2 | 3.4.13-2 |
| apache | zookeeper | >= 0 < 3.4.13-5ubuntu0.1 | 3.4.13-5ubuntu0.1 |
| apache | zookeeper | >= 0 < 3.4.13-6ubuntu4.1 | 3.4.13-6ubuntu4.1 |
| apache | zookeeper | >= 0 < 3.4.5+dfsg-1ubuntu0.1~esm3 | 3.4.5+dfsg-1ubuntu0.1~esm3 |
| apache | zookeeper | >= 0 < 3.4.8-1ubuntu0.1~esm2 | 3.4.8-1ubuntu0.1~esm2 |
| apache | zookeeper | >= 0 < 3.4.13-3ubuntu0.1~esm1 | 3.4.13-3ubuntu0.1~esm1 |
| apache | zookeeper | 1.0.0 – 3.4.13 | — |
| apache_software_foundation | apache_zookeeper | — | — |
| apache_software_foundation | apache_zookeeper | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | zookeeper | < zookeeper 3.4.13-2 (bookworm) | zookeeper 3.4.13-2 (bookworm) |
| oracle | goldengate_stream_analytics | < 19.1.0.0.1 | 19.1.0.0.1 |
| oracle | siebel_core_server_framework | <= 21.5 | — |
| oracle | timesten_in-memory_database | < 18.1.3.1.0 | 18.1.3.1.0 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ZooKeeper vulnerabilities
vendor_ubuntu·2024-01-16·CVSS 5.9
CVE-2023-44981 [MEDIUM] ZooKeeper vulnerabilities
Title: ZooKeeper vulnerabilities
Summary: Several security issues were fixed in ZooKeeper.
It was discovered that ZooKeeper incorrectly handled authorization for
the getACL() command. A remote attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2019-0201)
Damien Diederen discovered that ZooKeeper incorrectly handled
authorization if SASL Quorum Peer authentication is enabled. An
attacker could possibly use this issue to bypass ZooKeeper's
authorization system. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 23.04
and Ubuntu 23.10. (CVE-2023-44981)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache ZooKeeper) — CVE-2019-0201
vendor_oracle·2020-10-15·CVSS 5.9
CVE-2019-0201 [MEDIUM] Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache ZooKeeper) — CVE-2019-0201
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache ZooKeeper) vulnerability
CVE: CVE-2019-0201
CVSS: 5.9
Protocol: ZAB
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Red Hat
zookeeper: Information disclosure in Apache ZooKeeper
vendor_redhat·2019-05-20·CVSS 5.9
CVE-2019-0201 [MEDIUM] CWE-732 zookeeper: Information disclosure in Apache ZooKeeper
zookeeper: Information disclosure in Apache ZooKeeper
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
A flaw was found in Apache ZooKeeper. A lack of permission checks while retrieving ACLs allows unsalted hash values to be disclosed for unauthenticated or unprivileged users.
Mitigation: Use an authentica
Debian
CVE-2019-0201: zookeeper - An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4...
vendor_debian·2019·CVSS 5.9
CVE-2019-0201 [MEDIUM] CVE-2019-0201: zookeeper - An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4...
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
Scope: local
bookworm: resolved (fixed in 3.4.13-2)
bullseye: resolved (fixed in 3.4.13-2)
forky: resolved (fixed in 3.4.13-2)
sid: resolved (fixed in 3.4.13-2)
trixie: resolved (fixed in 3.4.13-2)
OSV
zookeeper vulnerabilities
osv·2024-01-16·CVSS 5.9
CVE-2019-0201 [MEDIUM] zookeeper vulnerabilities
zookeeper vulnerabilities
It was discovered that ZooKeeper incorrectly handled authorization for
the getACL() command. A remote attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2019-0201)
Damien Diederen discovered that ZooKeeper incorrectly handled
authorization if SASL Quorum Peer authentication is enabled. An
attacker could possibly use this issue to bypass ZooKeeper's
authorization system. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 23.04
and Ubuntu 23.10. (CVE-2023-44981)
GHSA
Access control bypass in Apache ZooKeeper
ghsa·2019-05-29
CVE-2019-0201 [MEDIUM] CWE-862 Access control bypass in Apache ZooKeeper
Access control bypass in Apache ZooKeeper
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper?s getACL() command doesn?t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
OSV
Access control bypass in Apache ZooKeeper
osv·2019-05-29
CVE-2019-0201 [MEDIUM] Access control bypass in Apache ZooKeeper
Access control bypass in Apache ZooKeeper
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper?s getACL() command doesn?t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
OSV
CVE-2019-0201: An issue is present in Apache ZooKeeper 1
osv·2019-05-23·CVSS 5.9
CVE-2019-0201 [MEDIUM] CVE-2019-0201: An issue is present in Apache ZooKeeper 1
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper
bugzilla·2019-05-29·CVSS 5.9
CVE-2019-0201 [MEDIUM] CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper
CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper's getACL() command doesn't check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
References:
http://www.securityfocus.com/bid/108427
https://issues.apache.org/jira/browse/ZOOKEEPER-1392
https://zookeeper.apache.org/security.html#CVE-2019-0201
Discussion:
Created zookee
Bugzilla
CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper [fedora-all]
bugzilla·2019-05-29·CVSS 5.9
CVE-2019-0201 [MEDIUM] CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper [fedora-all]
CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
http://www.securityfocus.com/bid/108427https://access.redhat.com/errata/RHSA-2019:3140https://access.redhat.com/errata/RHSA-2019:3892https://access.redhat.com/errata/RHSA-2019:4352https://issues.apache.org/jira/browse/ZOOKEEPER-1392https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/5d9a1cf41a5880557bf680b7321b4ab9a4d206c601ffb15fef6f196a%40%3Ccommits.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f6112882e30a31992a79e0a8c31ac179e9d0de7c708de3a9258d4391%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r40f32125c1d97ad82404cc918171d9e0fcf78e534256674e9da1eb4b%40%3Ccommon-issues.hadoop.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/05/msg00033.htmlhttps://seclists.org/bugtraq/2019/Jun/13https://security.netapp.com/advisory/ntap-20190619-0001/https://www.debian.org/security/2019/dsa-4461https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://zookeeper.apache.org/security.html#CVE-2019-0201http://www.securityfocus.com/bid/108427https://access.redhat.com/errata/RHSA-2019:3140https://access.redhat.com/errata/RHSA-2019:3892https://access.redhat.com/errata/RHSA-2019:4352https://issues.apache.org/jira/browse/ZOOKEEPER-1392https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/5d9a1cf41a5880557bf680b7321b4ab9a4d206c601ffb15fef6f196a%40%3Ccommits.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f6112882e30a31992a79e0a8c31ac179e9d0de7c708de3a9258d4391%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r40f32125c1d97ad82404cc918171d9e0fcf78e534256674e9da1eb4b%40%3Ccommon-issues.hadoop.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/05/msg00033.htmlhttps://seclists.org/bugtraq/2019/Jun/13https://security.netapp.com/advisory/ntap-20190619-0001/https://www.debian.org/security/2019/dsa-4461https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://zookeeper.apache.org/security.html#CVE-2019-0201
2019-05-23
Published