Apache Ozone是一个应用软件。一个面向Hadoop和云原生环境的可伸缩,冗余和分布式对象存储。 Apache Ozone 中存在输入验证错误漏洞,该漏洞源于产品的Ozone Datanode未检查block令牌的访问模式参数。攻击者可通过该漏洞使用具有READ权限的令牌执行写操作。以下产品及版本受到影响: Apache Ozone 1.2.0 之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Ozone | 1.0 ~ 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41532 | Unauthenticated access to Ozone Recon HTTP endpoints | |
| CVE-2021-39236 | Owners of the S3 tokens are not validated | |
| CVE-2021-39234 | Raw block data can be read bypassing ACL/authorization | |
| CVE-2021-39233 | Container-related datanode operations can be called without authorization | |
| CVE-2021-39232 | Missing admin check for SCM related admin commands | |
| CVE-2021-39231 | Missing authentication/authorization on internal RPC endpoints | |
| CVE-2021-36372 | Original block tokens are persisted and can be retrieved |
No comments yet