CVE-2021-39232

HIGH8.8EPSS 0.39%

Incorrect Authorization in Apache Ozone

Published: 11/23/2021Modified: 11/14/2023

Description

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)