Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20316
HistoryMay 24, 2019 - 3:01 a.m.

Information Disclosure

2019-05-2403:01:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

39.7%

Apache ZooKeeper is affected by unauthorized information disclosure. getACL() command does not check permissions when retrieving the ACLs of the requested node. Consequently, plaintext information contained in the ACL Id field is returned. This allows an attacker to retrieve users’ Id and authentication digests, and gain access to the application on behalf of the user.

References