In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-862",
"CWE-863"
],
"nvd_published_at": "2021-11-19T10:15:00Z",
"github_reviewed_at": "2021-11-22T19:05:02Z"
}