PT-2021-22484 · Apache · Apache Ozone
Marton Elek
·
Published
2021-11-19
·
Updated
2021-11-23
·
CVE-2021-39234
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Ozone versions prior to 1.2.0
Description
The issue allows authenticated users who know the ID of an existing block to craft specific requests, granting them access to those blocks and bypassing security checks like Access Control Lists (ACL).
Recommendations
For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue.
Fix
Incorrect Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Ozone