CVE-2021-36372

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-36372
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-36372.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-36372
Aliases
Published
2021-11-19T10:15:07Z
Modified
2025-01-14T09:23:29.628631Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked.

References

Affected packages

Git / github.com/apache/ozone

Affected ranges

Type
GIT
Repo
https://github.com/apache/ozone
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

ozone-1.*

ozone-1.2.0-RC0