In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Ozone
APPApache< 1.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-39231CRITICAL9.1PL ✓same product
Apache Ozone: niezabezpieczone endpointy RPC umożliwiają nieautoryzowany dostęp do danych
CVE-2021-39233CRITICAL9.1PL ✓same product
Apache Ozone: brak autoryzacji żądań Datanode do kontenerów
CVE-2024-45106HIGH8.1same product
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated K...
CVE-2021-39236HIGH8.8same product
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM reque...
CVE-2021-39232HIGH8.8same product
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticat...