First published: Fri Nov 19 2021(Updated: )
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ozone | <1.2.0 | |
maven/org.apache.ozone:ozone-main | <1.2.0 | 1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39232 is a vulnerability in Apache Ozone versions prior to 1.2.0 that allows any authenticated user to execute certain admin SCM commands, instead of limiting them to admins only.
CVE-2021-39232 has a severity score of 8.8, which is classified as high.
To fix CVE-2021-39232, upgrade to Apache Ozone version 1.2.0 or later.
CVE-2021-39232 is associated with CWE-862: Missing Authorization.
You can find more information about CVE-2021-39232 in the following references: [1] http://www.openwall.com/lists/oss-security/2021/11/19/3, [2] https://mail-archives.apache.org/mod_mbox/ozone-dev/202111.mbox/%3C3c30a7f2-13a4-345e-6c8a-c23a2b937041%40apache.org%3E, [3] https://nvd.nist.gov/vuln/detail/CVE-2021-39232