Apache Ozone是一个应用软件。一个面向Hadoop和云原生环境的可伸缩,冗余和分布式对象存储。 Apache Ozone 1.2.0版本存在安全漏洞,攻击者可以检索数据库中的令牌数据并进行使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Ozone | 1.1 ~ 1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41532 | Unauthenticated access to Ozone Recon HTTP endpoints | |
| CVE-2021-39236 | Owners of the S3 tokens are not validated | |
| CVE-2021-39235 | Access mode of block tokens are not enforced | |
| CVE-2021-39234 | Raw block data can be read bypassing ACL/authorization | |
| CVE-2021-39233 | Container-related datanode operations can be called without authorization | |
| CVE-2021-39232 | Missing admin check for SCM related admin commands | |
| CVE-2021-39231 | Missing authentication/authorization on internal RPC endpoints |
No comments yet