Severity
6.8MEDIUM
EPSS
0.2%
top 57.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateNov 23

Description

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Incorrect Authorization in Apache Ozone2021-11-23
OSV
Incorrect Authorization in Apache Ozone2021-11-23
CVEList
Raw block data can be read bypassing ACL/authorization2021-11-19
CVE-2021-39234 (MEDIUM CVSS 6.8) | In Apache Ozone versions prior to 1 | cvebase.io