CVE-2021-41532
Unauthenticated access to Ozone Recon HTTP endpoints
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.
Affected products
Apache Software Foundation · Apache OzoneWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →