Lucene search

K
osvGoogleOSV:GHSA-GC37-9G7F-96FX
HistoryNov 23, 2021 - 6:17 p.m.

Apache Ozone exposes OM, SCM and Datanode metadata

2021-11-2318:17:50
Google
osv.dev
23
apache ozone
metadata
recon http
unauthenticated access

EPSS

0.001

Percentile

24.7%

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

EPSS

0.001

Percentile

24.7%

Related for OSV:GHSA-GC37-9G7F-96FX