You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ozone.apache.org by Siddharth Wagle <sw...@apache.org> on 2021/11/18 23:06:09 UTC

CVE-2021-39233: Apache Ozone: Container-related datanode operations can be called without authorization

Description:

Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. 

This issue is being tracked as HDDS-4729,HDDS-5236

Mitigation:

Upgrade to Apache Ozone release version 1.2.0

Credit:

Apache Ozone would like to thank Marton Elek for reporting this issue.


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@ozone.apache.org
For additional commands, e-mail: dev-help@ozone.apache.org