Vulnerabilities > CVE-2021-39234 - Incorrect Authorization vulnerability in Apache Ozone

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
high complexity
apache
CWE-863

Summary

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

Vulnerable Configurations

Part Description Count
Application
Apache
12

Common Weakness Enumeration (CWE)