Impact: Important Public Date: 2019-05-20 CWE: CWE-732 Bugzilla: 1715197: CVE-2019-0201 zookeeper: Information disclosure in Apache ZooKeeper An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeepers getACL() command doesnt check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2019-0201 from the MITRE CVE dictionary dictionary and NIST NVD.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 7.5 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity Impact | None |
Availability Impact | None |
Platform | Package | State |
---|---|---|
Red Hat OpenShift Application Runtimes 1.0 | vertx | Under investigation |
Red Hat JBoss Fuse Service Works 6 | zookeeper | Under investigation |
Red Hat JBoss Fuse 7 | zookeeper | Under investigation |
Red Hat JBoss Fuse 6 | zookeeper | Under investigation |
Red Hat JBoss Data Virtualization 6 | zookeeper | Under investigation |
Red Hat JBoss BRMS 6 | zookeeper | Under investigation |
Red Hat JBoss BPMS 6 | zookeeper | Under investigation |
Red Hat JBoss A-MQ 6 | zookeeper | Under investigation |