CVE-2021-39235

Description

In Apache Ozone before 1.2.0, Ozone Datanode doesnt check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.367

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Apache-ozone-main 1.2.0Windows
Multiple vulnerabilities are fixed in Apache-ozone-main for Linux 1.2.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234