{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-16T05:55:21.107","vulnerabilities":[{"cve":{"id":"CVE-2019-0201","sourceIdentifier":"security@apache.org","published":"2019-05-23T14:29:07.517","lastModified":"2024-11-21T04:16:28.487","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users."},{"lang":"es","value":"Hay un problema presente en Apache ZooKeeper 1.0.0 a 3.4.13 y 3.5.0-alpha a 3.5.4-beta. El comando getACL () de ZooKeeper no verifica ningún permiso cuando recupera las ACL del nodo solicitado y devuelve toda la información contenida en el campo Id. De ACL como cadena de texto sin formato. DigestAuthenticationProvider sobrecarga el campo Id con el valor hash que se utiliza para la autenticación del usuario. Como consecuencia, si la autenticación implícita está en uso, el valor hash sin sal será revelado por la solicitud getACL () para usuarios no autenticados o no privilegiados."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:activemq:5.15.9:*:*:*:*:*:*:*","matchCriteriaId":"70B11FEF-4CBF-4483-A5BD-CDA5AFAE52AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:drill:1.16.0:*:*:*:*:*:*:*","matchCriteriaId":"235DC57F-22B8-4219-9499-7D005D90A654"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0","versionEndIncluding":"3.4.13","matchCriteriaId":"19FD698D-914D-46C3-810B-F749CD0C0DE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.0:-:*:*:*:*:*:*","matchCriteriaId":"3B1074FD-02DC-4CDC-A8F2-4CE0827539B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.0:alpha:*:*:*:*:*:*","matchCriteriaId":"2F0F84E2-88CE-4350-B342-DA761D43682E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.0:rc0:*:*:*:*:*:*","matchCriteriaId":"ACB3229A-F1BA-4AA7-916A-9061BE561AD4"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:-:*:*:*:*:*:*","matchCriteriaId":"0E5C9D62-F9A2-4961-8440-9DF6F5C213D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:alpha:*:*:*:*:*:*","matchCriteriaId":"A0C88D5A-86CD-41D3-B453-6060482E84E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:rc0:*:*:*:*:*:*","matchCriteriaId":"24BEEE1F-5408-43F8-B662-B826349E97D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:rc1:*:*:*:*:*:*","matchCriteriaId":"4031DB88-F356-458F-BC77-91B62744A466"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:rc2:*:*:*:*:*:*","matchCriteriaId":"AB019BEC-6C42-4A51-9C45-389B6529CE96"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:rc3:*:*:*:*:*:*","matchCriteriaId":"107E465A-A904-4198-8171-3D764B9F1C19"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.1:rc4:*:*:*:*:*:*","matchCriteriaId":"D5DE5D25-B8A9-4172-80FF-D430D47AE96A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.2:-:*:*:*:*:*:*","matchCriteriaId":"3E2EB460-5B43-42E3-98AF-FB08B0C94957"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.2:alpha:*:*:*:*:*:*","matchCriteriaId":"9C89705C-D40E-4C7D-A019-809D32AC1A98"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.2:rc0:*:*:*:*:*:*","matchCriteriaId":"738C3017-324B-46AB-8D71-5202E31DBC97"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.2:rc1:*:*:*:*:*:*","matchCriteriaId":"39BE8DA0-6839-4E59-838F-E0D6A4F96D3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.3:-:*:*:*:*:*:*","matchCriteriaId":"09C66E38-BDA9-42A6-8DBE-4E8781AE8394"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.3:beta:*:*:*:*:*:*","matchCriteriaId":"81C99F52-0D85-41C8-A0DA-CE29C917ADDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.3:rc0:*:*:*:*:*:*","matchCriteriaId":"9B94B4B9-2B39-4879-BC68-2E4DEC57650D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.3:rc1:*:*:*:*:*:*","matchCriteriaId":"3E6AADAF-368B-4143-AE49-736A4101D732"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:zookeeper:3.5.4:beta:*:*:*:*:*:*","matchCriteriaId":"C392B5BC-1B19-49CB-B43F-D485EC4DC094"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:fuse:1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"0F31D7E8-D31D-4268-9ABF-3733915AA226"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:goldengate_stream_analytics:*:*:*:*:*:*:*:*","versionEndExcluding":"19.1.0.0.1","matchCriteriaId":"F4E7F2AA-B851-4D85-9895-2CDD6BE9FCB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:siebel_core_-_server_framework:*:*:*:*:*:*:*:*","versionEndIncluding":"21.5","matchCriteriaId":"F9C855EA-6E35-4EFF-ADEB-0EDFF90272BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*","versionEndExcluding":"18.1.3.1.0","matchCriteriaId":"3CFFA207-BDA9-4088-890E-99D9A30421D8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*","matchCriteriaId":"1C767AA1-88B7-48F0-9F31-A89D16DCD52C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*","matchCriteriaId":"AD7447BC-F315-4298-A822-549942FC118B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*","matchCriteriaId":"85DF4B3F-4BBC-42B7-B729-096934523D63"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/108427","source":"security@apache.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3140","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3892","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:4352","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://issues.apache.org/jira/browse/ZOOKEEPER-1392","source":"security@apache.org","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/5d9a1cf41a5880557bf680b7321b4ab9a4d206c601ffb15fef6f196a%40%3Ccommits.accumulo.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/f6112882e30a31992a79e0a8c31ac179e9d0de7c708de3a9258d4391%40%3Cissues.bookkeeper.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r40f32125c1d97ad82404cc918171d9e0fcf78e534256674e9da1eb4b%40%3Ccommon-issues.hadoop.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00033.html","source":"security@apache.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://seclists.org/bugtraq/2019/Jun/13","source":"security@apache.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20190619-0001/","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2019/dsa-4461","source":"security@apache.org","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","source":"security@apache.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","source":"security@apache.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","source":"security@apache.org","tags":["Patch","Third Party Advisory"]},{"url":"https://zookeeper.apache.org/security.html#CVE-2019-0201","source":"security@apache.org","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/108427","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3140","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3892","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:4352","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://issues.apache.org/jira/browse/ZOOKEEPER-1392","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/5d9a1cf41a5880557bf680b7321b4ab9a4d206c601ffb15fef6f196a%40%3Ccommits.accumulo.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/f6112882e30a31992a79e0a8c31ac179e9d0de7c708de3a9258d4391%40%3Cissues.bookkeeper.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r40f32125c1d97ad82404cc918171d9e0fcf78e534256674e9da1eb4b%40%3Ccommon-issues.hadoop.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/05/msg00033.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://seclists.org/bugtraq/2019/Jun/13","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20190619-0001/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2019/dsa-4461","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://zookeeper.apache.org/security.html#CVE-2019-0201","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}