Container-related datanode operations can be called without authorization
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.
Affected products
Apache Software Foundation · Apache Ozone