9.8
CVSSv3

CVE-2021-36372

Published: 19/11/2021 Updated: 31/01/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Apache Ozone versions before 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ozone

Mailing Lists

Description: Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key Authenticated users may use them even after access is revoked This issue is being tracked as HDDS-5315 Mitigation: Upgrade to Apache Ozone release version 120 Credit: Apache Ozone ...