Описание
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListMitigationVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.0 (исключая)
cpe:2.3:a:apache:ozone:*:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01238
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-862
CWE-862
Связанные уязвимости
CVSS3: 9.1
github
около 4 лет назад
Exposure of sensitive information in Apache Ozone
EPSS
Процентиль: 79%
0.01238
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-862
CWE-862