← volver
CVE-2021-39236

Owners of the S3 tokens are not validated

EPSS 2.5%CWE-862
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →