First published: Fri Nov 19 2021(Updated: )
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ozone | <1.2.0 | |
maven/org.apache.ozone:ozone-main | <1.2.0 | 1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39235 is a vulnerability in Apache Ozone where the access mode of block tokens is not enforced.
CVE-2021-39235 allows authenticated users with a valid READ block token to perform any write operation on the same block.
CVE-2021-39235 has a severity rating of 6.5 (medium).
CVE-2021-39235 affects Apache Ozone versions up to and excluding 1.2.0.
To mitigate CVE-2021-39235, it is recommended to update Apache Ozone to version 1.2.0 or later.