{"id":"GHSA-gc37-9g7f-96fx","summary":"Apache Ozone exposes OM, SCM and Datanode metadata","details":"In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.","aliases":["CVE-2021-41532"],"modified":"2023-11-08T04:06:59.658462Z","published":"2021-11-23T18:17:50Z","database_specific":{"nvd_published_at":"2021-11-19T10:15:00Z","cwe_ids":["CWE-668"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-11-22T18:38:16Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41532"},{"type":"WEB","url":"https://mail-archives.apache.org/mod_mbox/ozone-dev/202111.mbox/%3Ce0bc6598-9669-b897-fc28-de8a896e36aa%40apache.org%3E"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2021/11/19/8"}],"affected":[{"package":{"name":"org.apache.ozone:ozone-main","ecosystem":"Maven","purl":"pkg:maven/org.apache.ozone/ozone-main"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-gc37-9g7f-96fx/GHSA-gc37-9g7f-96fx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}