First published: Fri Nov 19 2021(Updated: )
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ozone | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39236 is a vulnerability in Apache Ozone where authenticated users with valid Ozone S3 credentials can impersonate any other user.
The severity of CVE-2021-39236 is high, with a severity value of 8.8.
CVE-2021-39236 affects Apache Ozone before version 1.2.0.
Authenticated users with valid Ozone S3 credentials can exploit CVE-2021-39236 by creating specific OM requests to impersonate any other user.
You can find more information about CVE-2021-39236 at the following references: NVD, Openwall, and GitHub.