CVE-2021-39231

CVE-2021-39231: Missing authentication/authorization on internal RPC endpoints

Vendor Apache Software Foundation
Product Apache Ozone
Weakness CWE-862 · Missing authorization
Published November 19, 2021
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

Key dates

02Disclosure timeline

November 19, 2021 CVE published
August 4, 2024 Record updated