6.4
CVSSv2

CVE-2021-39231

Published: 19/11/2021 Updated: 21/01/2024
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Apache Ozone versions before 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an malicious user to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ozone

Mailing Lists

Description: Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration This issue is being tracked as HDDS-4704,HDDS-4730,HDDS-4496,HDDS-4788 Mitigation: Upgrade to Apache Ozone release versi ...