CVE-2021-36372
Summary
| CVE | CVE-2021-36372 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-19 10:15:00 UTC |
| Updated | 2024-01-31 10:15:00 UTC |
| Description | In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked. |
Risk And Classification
Problem Types: CWE-273
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE-2021-36372: Apache Ozone: Original block tokens are persisted and can be retrieved | MLIST | www.openwall.com | |
| CVE-2021-36372: Apache Ozone: Original block tokens are persisted and can be retrieved | MISC | mail-archives.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Apache Ozone would like to thank Marton Elek for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.