In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c6j7-4fr9-c76p | Incorrect permissions in Apache Ozone |
Fixes
Solution
No solution given by the vendor.
Workaround
Upgrade to Apache Ozone release version 1.2.0
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T02:06:41.327Z
Reserved: 2021-08-17T00:00:00
Link: CVE-2021-39235
No data.
Status : Modified
Published: 2021-11-19T10:15:08.303
Modified: 2024-11-21T06:18:58.673
Link: CVE-2021-39235
No data.
OpenCVE Enrichment
No data.
Github GHSA