The S3 buckets and keys in a secure Apache Ozone Cluster...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 27, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 27, 2023
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to buckets and keys thereby exposing data to anonymous clients or users. This affected Apache Ozone prior to the 1.1.0 release. Improper Authorization vulnerability in COMPONENT of Apache Ozone allows an attacker to IMPACT. This issue affects Apache Ozone Apache Ozone version 1.0.0 and prior versions.
References