CVE-2021-39236
published 2021-11-19CVE-2021-39236: In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.48%
82.7th percentile
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ozone | < 1.2.0 | 1.2.0 |
| apache_software_foundation | apache_ozone | 1.0 – 1.0 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Ozone user impersonation due to non-validation of Ozone S3 tokens
osv·2021-11-23
CVE-2021-39236 [HIGH] Apache Ozone user impersonation due to non-validation of Ozone S3 tokens
Apache Ozone user impersonation due to non-validation of Ozone S3 tokens
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
GHSA
Apache Ozone user impersonation due to non-validation of Ozone S3 tokens
ghsa·2021-11-23
CVE-2021-39236 [HIGH] CWE-862 Apache Ozone user impersonation due to non-validation of Ozone S3 tokens
Apache Ozone user impersonation due to non-validation of Ozone S3 tokens
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/11/19/7https://issues.apache.org/jira/browse/HDDS-4763https://mail-archives.apache.org/mod_mbox/ozone-dev/202111.mbox/%3C0fd74baa-88a0-39a2-8f3a-b982acb25d5a%40apache.org%3Ehttp://www.openwall.com/lists/oss-security/2021/11/19/7https://issues.apache.org/jira/browse/HDDS-4763https://mail-archives.apache.org/mod_mbox/ozone-dev/202111.mbox/%3C0fd74baa-88a0-39a2-8f3a-b982acb25d5a%40apache.org%3E
2021-11-19
Published