ZeroHour

CVE-2021-39235

CVSS 3.1
6.5 medium
EPSS
2%p73
Published
()
Modified
Description

In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

Vendors
apache
Products
ozone
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.