Lucene search

K
cvelistApacheCVELIST:CVE-2021-39235
HistoryNov 19, 2021 - 9:20 a.m.

CVE-2021-39235 Access mode of block tokens are not enforced

2021-11-1909:20:23
CWE-732
apache
www.cve.org
3
cve-2021-39235
apache ozone
block tokens
access mode
security vulnerability

EPSS

0.001

Percentile

34.2%

In Apache Ozone before 1.2.0, Ozone Datanode doesn’t check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

CNA Affected

[
  {
    "product": "Apache Ozone",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "1.0",
        "status": "affected",
        "version": "1.0",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

34.2%

Related for CVELIST:CVE-2021-39235