PT-2021-22483 · Apache · Apache Ozone

Marton Elek

·

Published

2021-11-19

·

Updated

2022-07-12

·

CVE-2021-39233

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Ozone versions prior to 1.2.0
Description The issue arises from the lack of proper authorization for Container related Datanode requests in Apache Ozone, allowing any client to make these requests.
Recommendations For Apache Ozone versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue.

Fix

Incorrect Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39233
GHSA-33XH-XCH9-P6HJ

Affected Products

Apache Ozone