Improper Authentication Vulnerability in Apache Ozone
CVE-2023-39196

5.3MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
7 February 2024

Summary

An improper authentication vulnerability exists in the Storage Container Manager of Apache Ozone that permits an attacker to access and download internal metadata without the necessary authentication. Although this issue does not allow any modifications within the Ozone Storage Container Manager service, the accessible metadata does not expose sensitive information or grant access to actual user data. Affected versions include Apache Ozone from 1.2.0 up to 1.3.0. Users are urged to upgrade to version 1.4.0 to mitigate this vulnerability.

Affected Version(s)

Apache Ozone 1.2.0 <= 1.3.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.