Apache Ozone Datanode Access Mode Parameter Vulnerability

Apache Ozone Datanode Access Mode Parameter Vulnerability

CVE-2021-39235 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

Learn more about our Cis Benchmark Audit For Apache Http Server.