Apache Ozone Datanode Access Mode Parameter Vulnerability
CVE-2021-39235 · MEDIUM Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
Learn more about our Cis Benchmark Audit For Apache Http Server.