CVE-2019-0201 Details
Description
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | 5.15.9 |
CPE
Remediation
| |
| apache drill | 1.16.0 |
CPE
Remediation
| |
| apache zookeeper | >= 1.0.0, <= 3.4.13 3.5.0 - 3.5.0 alpha 3.5.0 rc0 3.5.1 - 3.5.1 alpha 3.5.1 rc0 3.5.1 rc1 3.5.1 rc2 3.5.1 rc3 3.5.1 rc4 3.5.2 - 3.5.2 alpha 3.5.2 rc0 3.5.2 rc1 3.5.3 - 3.5.3 beta 3.5.3 rc0 3.5.3 rc1 3.5.4 beta |
CPE
Remediation
| |
| debian debian linux | 8.0 9.0 |
CPE
Remediation
| |
| redhat fuse | 1.0.0 |
CPE
Remediation
| |
| oracle goldengate stream analytics | < 19.1.0.0.1 |
CPE
Remediation
| |
| oracle siebel core - server framework | <= 21.5 |
CPE
Remediation
| |
| oracle timesten in-memory database | < 18.1.3.1.0 |
CPE
Remediation
| |
| netapp hci bootstrap os | All versions |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| netapp element software | All versions |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 19, 2022 | Modified Analysis | [email protected] |
| Aug 16, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| Feb 10, 2020 | CVE Modified | [email protected] |
| Dec 19, 2019 | CVE Modified | [email protected] |
| Nov 15, 2019 | CVE Modified | [email protected] |
| Oct 21, 2019 | CVE Modified | [email protected] |
| Oct 17, 2019 | CVE Modified | [email protected] |
| Oct 17, 2019 | CVE Modified | [email protected] |
| Aug 21, 2019 | CVE Modified | [email protected] |
| Jun 19, 2019 | CVE Modified | [email protected] |
| Jun 12, 2019 | CVE Modified | [email protected] |
| Jun 12, 2019 | CVE Modified | [email protected] |
| Jun 5, 2019 | CVE Modified | [email protected] |
| May 31, 2019 | CVE Modified | [email protected] |
| May 24, 2019 | Initial Analysis | [email protected] |
| May 24, 2019 | CVE Modified | [email protected] |