📦 Ozone

by Apache

🔍 What is Ozone?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-39231

CRITICAL CVSS 9.1 Nov 19, 2021

Apache Ozone versions before 1.2.0 expose internal RPC endpoints that allow attackers to download raw data from Datanode and Ozone Manager components, and modify Ratis replication configuration. This ...

CVE-2021-39233

CRITICAL CVSS 9.1 Nov 19, 2021

This vulnerability allows any client to make unauthorized container-related DataNode requests to Apache Ozone, bypassing authentication mechanisms. It affects Apache Ozone installations prior to versi...

CVE-2024-45106

HIGH CVSS 8.1 Dec 3, 2024

This vulnerability in Apache Ozone's S3 Gateway allows any authenticated Kerberos user to revoke and regenerate S3 secrets of any other user, potentially causing denial of service or privilege escalat...

CVE-2021-39236

HIGH CVSS 8.8 Nov 19, 2021

This vulnerability allows authenticated users with valid Ozone S3 credentials to impersonate any other user by creating specific OM requests. It affects Apache Ozone deployments where users have S3 cr...

CVE-2020-17517

HIGH CVSS 7.5 Apr 27, 2021

This vulnerability allows unauthenticated access to S3 buckets and keys in Apache Ozone clusters through simple HTTP requests or curl commands. It affects all Apache Ozone deployments prior to version...