In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c6j7-4fr9-c76p Incorrect permissions in Apache Ozone
Fixes

Solution

No solution given by the vendor.


Workaround

Upgrade to Apache Ozone release version 1.2.0

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T02:06:41.327Z

Reserved: 2021-08-17T00:00:00

Link: CVE-2021-39235

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-19T10:15:08.303

Modified: 2024-11-21T06:18:58.673

Link: CVE-2021-39235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.