First published: Fri Nov 19 2021(Updated: )
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ozone | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-39234.
The severity rating of CVE-2021-39234 is medium.
CVE-2021-39234 is a vulnerability in Apache Ozone versions prior to 1.2.0 that allows authenticated users to bypass security checks and access blocks.
The affected software by CVE-2021-39234 is Apache Ozone versions prior to 1.2.0.
To fix CVE-2021-39234, upgrade to Apache Ozone version 1.2.0 or later.