CVE-2021-36372

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 0.16 % (53th)
0.16% Progress
Affected Products 1
Advisories 1

In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked.

Weaknesses
CWE-273
Improper Check for Dropped Privileges
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-11-19 10:15:07
(2 years ago)
Updated Date
2024-01-31 10:15:08
(7 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Ozone prior 1.2.0 version cpe:2.3:a:apache:ozone < 1.2.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...