Lucene search

K
redhatcveRedhat.comRH:CVE-2019-0201
HistoryMay 29, 2019 - 7:50 p.m.

CVE-2019-0201

2019-05-2919:50:10
redhat.com
access.redhat.com
16

0.001 Low

EPSS

Percentile

39.7%

A flaw was found in Apache ZooKeeper. A lack of permission checks while retrieving ACLs allows unsalted hash values to be disclosed for unauthenticated or unprivileged users.

Mitigation

Use an authentication method other than Digest (e.g. Kerberos) or upgrade to zookeeper 3.4.14 or later (3.5.5 or later if on the 3.5 branch). [<https://zookeeper.apache.org/security.html#CVE-2019-0201&gt;]