Lucene search

K
osvGoogleOSV:GHSA-C6J7-4FR9-C76P
HistoryNov 23, 2021 - 6:17 p.m.

Incorrect permissions in Apache Ozone

2021-11-2318:17:41
Google
osv.dev
20
apache ozone
permissions
vulnerability
access mode
datanode

EPSS

0.001

Percentile

34.2%

In Apache Ozone before 1.2.0, Ozone Datanode doesn’t check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

EPSS

0.001

Percentile

34.2%

Related for OSV:GHSA-C6J7-4FR9-C76P