logo

CVE-2021-39233 org.apache.ozone:ozone-main

Package

Manager: maven
Name: org.apache.ozone:ozone-main
Vulnerable Version: >=0 <1.2.0

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.01634 pctl0.81204

Details

Incorrect Authorization in Apache Ozone In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

Metadata

Created: 2021-11-23T18:17:59Z
Modified: 2021-11-22T18:36:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-33xh-xch9-p6hj/GHSA-33xh-xch9-p6hj.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-33xh-xch9-p6hj
Finding: F006
Auto approve: 1