Lucene search

K
osvGoogleOSV:CVE-2021-41532
HistoryNov 19, 2021 - 10:15 a.m.

CVE-2021-41532

2021-11-1910:15:08
Google
osv.dev
5
apache ozone
recon http endpoints
bug
unauthenticated access
metadata

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

24.7%

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

24.7%