Improper Authentication Vulnerability in Apache Ozone
CVE-2023-39196
5.3MEDIUM
What is CVE-2023-39196?
An improper authentication vulnerability exists in the Storage Container Manager of Apache Ozone that permits an attacker to access and download internal metadata without the necessary authentication. Although this issue does not allow any modifications within the Ozone Storage Container Manager service, the accessible metadata does not expose sensitive information or grant access to actual user data. Affected versions include Apache Ozone from 1.2.0 up to 1.3.0. Users are urged to upgrade to version 1.4.0 to mitigate this vulnerability.
Affected Version(s)
Apache Ozone 1.2.0 <= 1.3.0