CVE-2019-0201

Related Vulnerabilities: CVE-2019-0201  

Impact: Important Public Date: 2019-05-20 CWE: CWE-732 Bugzilla: 1715197: CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeepers getACL() command doesnt check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.

The MITRE CVE dictionary describes this issue as:

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeepers getACL() command doesnt check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.

Find out more about CVE-2019-0201 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact None
Availability Impact None

Affected Packages State

Platform Package State
Red Hat OpenShift Application Runtimes 1.0 vertx Under investigation
Red Hat JBoss Fuse Service Works 6 zookeeper Under investigation
Red Hat JBoss Fuse 7 zookeeper Under investigation
Red Hat JBoss Fuse 6 zookeeper Under investigation
Red Hat JBoss Data Virtualization 6 zookeeper Under investigation
Red Hat JBoss BRMS 6 zookeeper Under investigation
Red Hat JBoss BPMS 6 zookeeper Under investigation
Red Hat JBoss A-MQ 6 zookeeper Under investigation