Unauthenticated access to Ozone Recon HTTP endpoints
CVE-2021-41532

5.3MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
19 November 2021

Summary

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

Affected Version(s)

Apache Ozone Everglades (1.1.0) <= 1.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Ozone would like to thank Ethan Rose for reporting this issue.
.