Severity
5.9MEDIUM
EPSS
0.2%
top 56.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateJan 16

Description

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages11 packages

Mavenorg.apache.zookeeper:zookeeper1.0.03.4.14+1
NVDapache/zookeeper1.0.03.4.13+5
CVEListV5apache_software_foundation/apache_zookeeper1.0.0 to 3.4.13, 3.5.0-alpha to 3.5.4-beta+1
Debianzookeeper< 3.4.13-2+3
Ubuntuzookeeper< 3.4.13-5ubuntu0.1+4

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

5
OSV
zookeeper vulnerabilities2024-01-16
GHSA
Access control bypass in Apache ZooKeeper2019-05-29
OSV
Access control bypass in Apache ZooKeeper2019-05-29
CVEList
CVE-2019-0201: An issue is present in Apache ZooKeeper 12019-05-23
OSV
CVE-2019-0201: An issue is present in Apache ZooKeeper 12019-05-23

📋Vendor Advisories

4
Ubuntu
ZooKeeper vulnerabilities2024-01-16
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache ZooKeeper) — CVE-2019-02012020-10-15
Red Hat
zookeeper: Information disclosure in Apache ZooKeeper2019-05-20
Debian
CVE-2019-0201: zookeeper - An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4...2019

💬Community

2
Bugzilla
CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper2019-05-29
Bugzilla
CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper [fedora-all]2019-05-29