6.4
CVSSv2

CVE-2021-39233

Published: 19/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Apache Ozone versions before 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ozone

Mailing Lists

Description: Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client This issue is being tracked as HDDS-4729,HDDS-5236 Mitigation: Upgrade to Apache Ozone release version 120 Credit: Apache Ozone would like to thank Marton Elek for reporting this issue ...