Improper Authentication Vulnerability in Apache Ozone
CVE-2023-39196
5.3MEDIUM
Summary
An improper authentication vulnerability exists in the Storage Container Manager of Apache Ozone that permits an attacker to access and download internal metadata without the necessary authentication. Although this issue does not allow any modifications within the Ozone Storage Container Manager service, the accessible metadata does not expose sensitive information or grant access to actual user data. Affected versions include Apache Ozone from 1.2.0 up to 1.3.0. Users are urged to upgrade to version 1.4.0 to mitigate this vulnerability.
Affected Version(s)
Apache Ozone 1.2.0 <= 1.3.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved