Lucene search

K
osvGoogleOSV:CVE-2021-39235
HistoryNov 19, 2021 - 10:15 a.m.

CVE-2021-39235

2021-11-1910:15:08
Google
osv.dev
6
apache
ozone
security
vulnerability
block token
access mode
authenticated users
write operation

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

34.2%

In Apache Ozone before 1.2.0, Ozone Datanode doesn’t check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

34.2%