Lucene search

K
osvGoogleOSV:CVE-2021-39236
HistoryNov 19, 2021 - 10:15 a.m.

CVE-2021-39236

2021-11-1910:15:08
Google
osv.dev
5
apache ozone
vulnerability
user impersonation
authenticated users
om requests
software security

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

68.1%

In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

68.1%