VendorsApacheozoneall versions
Vulnerabilities

Apache Software Foundation Ozone

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-36372
Original block tokens are persisted and can be retrieved
Published 2021-11-19 · Modified
9.8EPSS 0.025
CVE-2021-39231
Missing authentication/authorization on internal RPC endpoints
Published 2021-11-19 · Modified
9.1EPSS 0.024
CVE-2021-39233
Container-related datanode operations can be called without authorization
Published 2021-11-19 · Modified
9.1EPSS 0.024
CVE-2021-39236
Owners of the S3 tokens are not validated
Published 2021-11-19 · Modified
8.8EPSS 0.026
CVE-2021-39232
Missing admin check for SCM related admin commands
Published 2021-11-19 · Modified
8.8EPSS 0.017
CVE-2024-45106
Apache Ozone: Improper authentication when generating S3 secrets
Published 2024-12-03 · Analyzed
8.1EPSS 0.006
CVE-2020-17517
Ozone S3 Gateway allows bucket and key access to non authenticated users
Published 2021-04-27 · Modified
7.5EPSS 0.023
CVE-2021-39234
Raw block data can be read bypassing ACL/authorization
Published 2021-11-19 · Modified
6.8EPSS 0.014
CVE-2021-39235
Access mode of block tokens are not enforced
Published 2021-11-19 · Modified
6.5EPSS 0.016
CVE-2021-41532
Unauthenticated access to Ozone Recon HTTP endpoints
Published 2021-11-19 · Modified
5.3EPSS 0.024
CVE-2023-39196
Apache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpoints
Published 2024-02-07 · Modified
5.3EPSS 0.008