zookeeper: Information disclosure in Apache ZooKeeper
Published May 23, 2019
5.9
MEDIUMCVSS 3.1
EPSS 9.71%
Description
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
Affected products
-
- Version 1.0.0 to 3.4.13StatusaffectedConstraints-
- Version 3.5.0-alpha to 3.5.4-betaStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache ZooKeeper | n/a |
|
Configuration 1
- 5.15.9
- 1.16.0
- ≥ 1.0.0 · ≤ 3.4.13
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.2
- 3.5.2
- 3.5.2
- 3.5.2
- 3.5.3
- 3.5.3
- 3.5.3
- 3.5.3
- 3.5.4
Configuration 2
- 8.0
- 9.0
Configuration 4
- < 19.1.0.0.1
- ≤ 21.5
- < 18.1.3.1.0
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
No data.
Red Hat Fuse 6.3
zookeeper
Fixed · RHSA-2019:4352
Red Hat Fuse 6.3
zookeeper
Fixed · RHSA-2019:4352
Red Hat Fuse 7.5.0
zookeeper
Fixed · RHSA-2019:3892
Red Hat JBoss Data Virtualization 6.4.8
zookeeper
Fixed · RHSA-2019:3140
Red Hat BPM Suite 6
zookeeper
Out of support scope
Red Hat JBoss BRMS 6
zookeeper
Out of support scope
Red Hat JBoss Fuse Service Works 6
zookeeper
Out of support scope
Red Hat OpenShift Application Runtimes
zookeeper
Not affected
streams for Apache Kafka
zookeeper
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 6.3 | zookeeper | Fixed | RHSA-2019:4352 |
| Red Hat Fuse 6.3 | zookeeper | Fixed | RHSA-2019:4352 |
| Red Hat Fuse 7.5.0 | zookeeper | Fixed | RHSA-2019:3892 |
| Red Hat JBoss Data Virtualization 6.4.8 | zookeeper | Fixed | RHSA-2019:3140 |
| Red Hat BPM Suite 6 | zookeeper | Out of support scope | n/a |
| Red Hat JBoss BRMS 6 | zookeeper | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | zookeeper | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | zookeeper | Not affected | n/a |
| streams for Apache Kafka | zookeeper | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Use an authentication method other than Digest (e.g. Kerberos) or upgrade to zookeeper 3.4.14 or later (3.5.5 or later if on the 3.5 branch). [https://zookeeper.apache.org/security.html#CVE-2019-0201]
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.71% (0.09712) | 95.38th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.63% (0.09634) | 94.85th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.24% (0.00237) | 44.80th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00099) | 42.69th | v3 (v2023.03.01) |
| May 16, 2024 | 0.09% (0.00093) | 39.21th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.09% (0.00088) | 37.21th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.11% (0.00107) | 41.76th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.77% (0.07767) | 93.09th | v2 (v2022.01.01) |
| Apr 20, 2022 | 7.77% (0.07767) | 92.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.24% (0.05242) | 88.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 35.69% (0.35688) | 96.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 37.58% (0.37582) | 98.11th | v1 |
| Jan 6, 2022 | 37.58% (0.37582) | 98.08th | v1 |
| Sep 1, 2021 | 11.83% (0.11832) | 95.67th | v1 |
| Aug 17, 2021 | 11.83% (0.11832) | 0.00th | v1 |
| Jul 21, 2021 | 11.33% (0.11329) | 0.00th | v1 |
| Apr 14, 2021 | 10.82% (0.10820) | 0.00th | v1 |
References (32)
- http://www.securityfocus.com/bid/108427 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3140 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-0201 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1715197 Issue Tracking
- https://github.com/advisories/GHSA-2hw2-62cp-p9p7 Advisory
- https://issues.apache.org/jira/browse/ZOOKEEPER-1392 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/5d9a1cf41a5880557bf680b7321b4ab9a4d206c601ffb15fef6f196a%40%3Ccommits.accumulo.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5d9a1cf41a5880557bf680b7321b4ab9a4d206c601ffb15fef6f196a@%3Ccommits.accumulo.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f6112882e30a31992a79e0a8c31ac179e9d0de7c708de3a9258d4391%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f6112882e30a31992a79e0a8c31ac179e9d0de7c708de3a9258d4391@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/r40f32125c1d97ad82404cc918171d9e0fcf78e534256674e9da1eb4b%40%3Ccommon-issues.hadoop.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r40f32125c1d97ad82404cc918171d9e0fcf78e534256674e9da1eb4b@%3Ccommon-issues.hadoop.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/05/msg00033.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-0201
- https://seclists.org/bugtraq/2019/Jun/13 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190619-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-0201
- https://www.debian.org/security/2019/dsa-4461 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
- https://zookeeper.apache.org/security.html#CVE-2019-0201 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.