You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Siddharth Wagle <sw...@apache.org> on 2021/11/18 23:04:45 UTC
CVE-2021-39232: Apache Ozone: Missing admin check for SCM related admin commands
Description:
Certain admin related SCM commands can be executed by any authenticated users, not just by admins.
This issue is being tracked as HDDS-4530
Mitigation:
Upgrade to Apache Ozone release version 1.2.0
Credit:
Apache Ozone would like to thank Wei-Chiu Chuang for reporting this issue.