You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ozone.apache.org by Siddharth Wagle <sw...@apache.org> on 2021/11/18 23:07:46 UTC
CVE-2021-41532: Apache Ozone: Unauthenticated access to Ozone Recon HTTP endpoints
Severity: moderate
Description:
Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.
This issue is being tracked as HDDS-5691
Mitigation:
Upgrade to Apache Ozone release version 1.2.0
Credit:
Apache Ozone would like to thank Ethan Rose for reporting this issue.
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@ozone.apache.org
For additional commands, e-mail: dev-help@ozone.apache.org