4.9
CVSSv2

CVE-2021-39234

Published: 19/11/2021 Updated: 19/11/2021
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 5.2 | Exploitability Score: 1.6
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

In Apache Ozone versions before 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ozone

Mailing Lists

Description: Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL This issue is being tracked as HDDS-5061 Mitigation: Upgrade to Apache Ozone release version 120 Credit: Apache Ozone would like to thank Marton Elek for reporting this iss ...