CVE-2021-39235
—CVSS 3.1
6.5 medium
EPSS
2%p73
Published
()
Modified
Description
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
- Vendors
- apache
- Products
- ozone
- Weakness
- CWE-732
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.