In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2021-11-19T09:20:23

Updated: 2023-11-13T12:47:55.398Z

Reserved: 2021-08-17T00:00:00


Link: CVE-2021-39235

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-11-19T10:15:08.303

Modified: 2023-12-22T19:21:34.490


Link: CVE-2021-39235

JSON object: View

cve-icon Redhat Information

No data.

CWE