← Back

CVE-2021-39234

nvd nist
Published: Nov 19, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.6 / Impact: 5.2
Source: NVD

Description

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

Affected (1)

Products: Apache: Ozone
1 product
Ozone
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.2.0

References (4)

Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.