Unauthenticated access to Ozone Recon HTTP endpoints
CVE-2021-41532
5.3MEDIUM
Summary
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.
Affected Version(s)
Apache Ozone Everglades (1.1.0) <= 1.1.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Apache Ozone would like to thank Ethan Rose for reporting this issue.