Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3w5h-x4rh-hc28

Опубликовано: 23 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Exposure of sensitive information in Apache Ozone

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

Пакеты

Наименование

org.apache.ozone:ozone-main

maven
Затронутые версииВерсия исправления

< 1.2.0

1.2.0

EPSS

Процентиль: 79%
0.01238
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-668
CWE-862

Связанные уязвимости

CVSS3: 9.1
nvd
около 4 лет назад

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

EPSS

Процентиль: 79%
0.01238
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-668
CWE-862