In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.
2021-11-19T10:15:08.250
2024-11-21T06:18:58.523
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:N
6.8
4.9