SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0201

As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.

MEDIUM 5.9EPSS 9.71%

Does this matter?

Lower severity and a low EPSS score (9.71%). Track it; it rarely justifies an emergency change on its own.

Description

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
9.71% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
apache/activemq · apache/drill · apache/zookeeper · debian/debian linux · redhat/fuse · oracle/goldengate stream analytics · oracle/siebel core - server framework · oracle/timesten in-memory database · netapp/hci bootstrap os · netapp/element software
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.