You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Siddharth Wagle <sw...@apache.org> on 2021/11/18 23:07:24 UTC

CVE-2021-39236: Apache Ozone: Owners of the S3 tokens are not validated

Description:

Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. 

This issue is being tracked as HDDS-4763

Mitigation:

Upgrade to Apache Ozone release version 1.2.0

Credit:

Apache Ozone would like to thank Marton Elek for reporting this issue.