Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33043
HistoryNov 22, 2021 - 4:54 a.m.

Privilege Escalation

2021-11-2204:54:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
apache ozone common
privilege escalation
vulnerability
metadata database
authenticated users
malicious user
access
key

EPSS

0.002

Percentile

53.8%

Apache Ozone Common is vulnerable to privilege escalation attacks. The vulnerability exists because the initially generated block tokens are stored in metadata database and can be retrieved with authenticated users with permission, allowing a malicious user to gain access to the key even after access is revoked.

EPSS

0.002

Percentile

53.8%

Related for VERACODE:33043