Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Ozone
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-39235 1 Apache 1 Ozone 2023-12-22 4.0 MEDIUM 6.5 MEDIUM
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
CVE-2021-39234 1 Apache 1 Ozone 2021-11-19 4.9 MEDIUM 6.8 MEDIUM
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.
CVE-2021-41532 1 Apache 1 Ozone 2021-11-19 5.0 MEDIUM 5.3 MEDIUM
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.