Description
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.
Remediation
References
https://mail-archives.apache.org/mod_mbox/ozone-dev/202111.mbox/%3C110cd117-75ed-364b-cd38-3effd20f2183%40apache.org%3E
http://www.openwall.com/lists/oss-security/2021/11/19/2
Related Vulnerabilities
CVE-2023-34238 Vulnerability in npm package gatsby-cli
CVE-2020-2193 Vulnerability in maven package io.jenkins.plugins:echarts-api
CVE-2022-25867 Vulnerability in maven package io.socket:socket.io-client
CVE-2022-21704 Vulnerability in npm package log4js
CVE-2023-50709 Vulnerability in npm package @cubejs-backend/api-gateway