CVE-2021-39233 – org.apache.ozone:ozone-main
Package
Manager: maven
Name: org.apache.ozone:ozone-main
Vulnerable Version: >=0 <1.2.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.01634 pctl0.81204
Details
Incorrect Authorization in Apache Ozone In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.
Metadata
Created: 2021-11-23T18:17:59Z
Modified: 2021-11-22T18:36:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-33xh-xch9-p6hj/GHSA-33xh-xch9-p6hj.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-33xh-xch9-p6hj
Finding: F006
Auto approve: 1