Severity
9.1CRITICAL
EPSS
1.2%
top 21.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateNov 23

Description

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Incorrect Authorization in Apache Ozone2021-11-23
OSV
Incorrect Authorization in Apache Ozone2021-11-23
CVEList
Container-related datanode operations can be called without authorization2021-11-19
CVE-2021-39233 (CRITICAL CVSS 9.1) | In Apache Ozone versions prior to 1 | cvebase.io