← Back

CVE-2021-36372

nvd nist
Published: Nov 19, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked.

Affected (1)

Products: Apache: Ozone
1 product
Ozone
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.2.0

References (4)

Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationVendor Advisory

Timeline

No history available yet.