CVE-2021-39235
Summary
| CVE | CVE-2021-39235 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-19 10:15:00 UTC |
| Updated | 2023-12-22 19:21:00 UTC |
| Description | In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-39235: Apache Ozone: Access mode of block tokens are not enforced | MISC | mail-archives.apache.org | |
| oss-security - CVE-2021-39235: Apache Ozone: Access mode of block tokens are not enforced | MLIST | www.openwall.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Apache Ozone would like to thank Marton Elek for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.