8.8
CVSSv3

CVE-2021-39236

Published: 19/11/2021 Updated: 22/12/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In Apache Ozone prior to 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ozone

Mailing Lists

Description: Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user This issue is being tracked as HDDS-4763 Mitigation: Upgrade to Apache Ozone release version 120 Credit: Apache Ozone would like to thank Marton Elek for reporting this issue ...