HIGH🇬🇧 English

CVE-2024-45106

CVSS 8.1v3.1pub. 2024-12-03upd. 2025-07-01

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. The default value of this configuration is false. * The user configured in ozone.s3g.kerberos.principal is also configured in ozone.s3.administrators or ozone.administrators. Users are recommended to upgrade to Apache Ozone version 1.4.1 which disables the affected endpoint.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Apache Ozone

    APP
    Apache
    1.4.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2021-36372CRITICAL9.8PL ✓ten sam produkt

Apache Ozone: block tokeny dostępne po cofnięciu uprawnień

CVE-2021-39231CRITICAL9.1PL ✓ten sam produkt

Apache Ozone: niezabezpieczone endpointy RPC umożliwiają nieautoryzowany dostęp do danych

CVE-2021-39233CRITICAL9.1PL ✓ten sam produkt

Apache Ozone: brak autoryzacji żądań Datanode do kontenerów

CVE-2021-39236HIGH8.8ten sam produkt

In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM reque...

CVE-2021-39232HIGH8.8ten sam produkt

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticat...