Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-39232: Missing admin check for SCM related admin commands

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

CVE
#apache

Description:

Certain admin related SCM commands can be executed by any authenticated users, not just by admins.

This issue is being tracked as HDDS-4530

Mitigation:

Upgrade to Apache Ozone release version 1.2.0

Credit:

Apache Ozone would like to thank Wei-Chiu Chuang for reporting this issue.

To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907