Apache Ozone是一个应用软件。一个面向Hadoop和云原生环境的可伸缩,冗余和分布式对象存储。 Apache Ozone 中存在访问控制错误漏洞,该漏洞源于产品未对OM、SCM和Datanode元数据的访问添加有效的权限。攻击者可通过该漏洞访问敏感数据。以下产品及版本受到影响:Apache Ozone 1.2.0之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Ozone | Everglades (1.1.0) ~ 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-39236 | Owners of the S3 tokens are not validated | |
| CVE-2021-39235 | Access mode of block tokens are not enforced | |
| CVE-2021-39234 | Raw block data can be read bypassing ACL/authorization | |
| CVE-2021-39233 | Container-related datanode operations can be called without authorization | |
| CVE-2021-39232 | Missing admin check for SCM related admin commands | |
| CVE-2021-39231 | Missing authentication/authorization on internal RPC endpoints | |
| CVE-2021-36372 | Original block tokens are persisted and can be retrieved |
No comments yet