Lucene search

K
osvGoogleOSV:GHSA-5993-WWPG-M92C
HistoryNov 23, 2021 - 5:56 p.m.

Apache Ozone user impersonation due to non-validation of Ozone S3 tokens

2021-11-2317:56:45
Google
osv.dev
34
apache ozone
user impersonation
s3 tokens

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

68.1%

In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

68.1%

Related for OSV:GHSA-5993-WWPG-M92C