accumulo-master is vulnerable to authorization bypass. The vulnerability exists through improper handling of permissions check during canFlush
and canPerformSystemActions
.
www.openwall.com/lists/oss-security/2020/12/29/1
github.com/apache/accumulo/commit/58b9de18eb51e91aa9f01338ef5772ca92e329e6
github.com/apache/accumulo/pull/1828
lists.apache.org/thread.html/rf8c1a787b6951d3dacb9ec58f0bf1633790c91f54ff10c6f8ff9d8ed%40%3Cuser.accumulo.apache.org%3E
lists.apache.org/thread.html/rf8c1a787b6951d3dacb9ec58f0bf1633790c91f54ff10c6f8ff9d8ed@%3Cannounce.apache.org%3E