CVE-2021-39233

CRITICAL

Apache Ozone < 1.2.0 - Unauthenticated Container Request Access

Title source: llm
STIX 2.1

Description

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

References (2)

Core 2
Core References
Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/11/19/4

Scores

CVSS v3 9.1
EPSS 0.0065
EPSS Percentile 71.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-306
Status published
Products (2)
apache/ozone < 1.2.0
org.apache.ozone/ozone-main 0 - 1.2.0Maven
Published Nov 19, 2021
Tracked Since Feb 18, 2026