PT-2021-21257 · Apache · Apache Ozone

Marton Elek

·

Published

2021-11-19

·

Updated

2024-01-31

·

CVE-2021-36372

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Ozone versions prior to 1.2.0
Description The issue allows authenticated users with permission to the key to retrieve initially generated block tokens from the metadata database. These tokens can be used even after access has been revoked.
Recommendations For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-36372
GHSA-86FH-J58M-7PF5

Affected Products

Apache Ozone