Description
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1801-1 | zookeeper security update |
Debian DSA |
DSA-4461-1 | zookeeper security update |
EUVD |
EUVD-2019-0443 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users. |
Github GHSA |
GHSA-2hw2-62cp-p9p7 | Access control bypass in Apache ZooKeeper |
Ubuntu USN |
USN-6559-1 | ZooKeeper vulnerabilities |
References
History
No history.
Subscriptions
Apache
Subscribe
Activemq
Subscribe
Drill
Subscribe
Zookeeper
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Netapp
Subscribe
Element Software
Subscribe
Hci Bootstrap Os
Subscribe
Hci Compute Node
Subscribe
Oracle
Subscribe
Goldengate Stream Analytics
Subscribe
Siebel Core - Server Framework
Subscribe
Timesten In-memory Database
Subscribe
Redhat
Subscribe
Fuse
Subscribe
Jboss Amq
Subscribe
Jboss Data Virtualization
Subscribe
Jboss Fuse
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:44:14.871Z
Reserved: 2018-11-14T00:00:00.000Z
Link: CVE-2019-0201
No data.
Status : Modified
Published: 2019-05-23T14:29:07.517
Modified: 2024-11-21T04:16:28.487
Link: CVE-2019-0201
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN