Improper access control in ZooKeeper - CVE-2019-0201

 

Improper access control in ZooKeeper - CVE-2019-0201

Published: June 4, 2019 / Updated: October 27, 2020


Vulnerability identifier: #VU18668
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0201
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions when "getACL()" command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. A remote attacker can gain READ permissions to list ACL.


Affected software

ZooKeeper
Oracle TimesTen In-Memory Database
IBM PureData System for Operational Analytics
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
Planning Analytics Local
zookeeper (Debian package)
libzookeeper-java (Ubuntu package)
Fuse
JBoss Data Virtualization
IBM Security Guardium
Ubuntu
EMC ECS
StreamSets Data Collector

How to mitigate CVE-2019-0201

Install updates from vendor's website.

ZooKeeper - addressed in versions 3.4.14, 3.5.5
Planning Analytics Local - update to 2.0.1
zookeeper (Debian package) - update to 3.4.9-3+deb9u2
Fuse - addressed in versions 6.3.14, 7.5.0
JBoss Data Virtualization - update to 6.4.8
Oracle TimesTen In-Memory Database - update to 18.1.3.1.0
libzookeeper-java (Ubuntu package) - addressed in versions Ubuntu Pro, 3.4.13-5ubuntu0.1, 3.4.13-6ubuntu4.1, 3.8.0-10ubuntu0.1, 3.8.0-11ubuntu0.1
EMC ECS - update to 3.5.0.1
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.1, 6.1.2.0
StreamSets Data Collector - update to 7.0.0

External References

Related Security Bulletins