Ozone
Vendor:
First CVE: Apr 27, 2021 · Active for 5 years
11
Total CVEs
More Total CVEs than 89% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ozone over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2021
5 years ago
Most Recent CVE
Dec 3, 2024
598 days ago
CVE Severity & Scoring
Ozone11 CVEs
36%
36%
27%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36372CRITICAL In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to th | Nov 19, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-39233CRITICAL In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. | Nov 19, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-39236HIGH In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. | Nov 19, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-39231CRITICAL In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from | Nov 19, 2021 | 9.1 | 28 | NO | NO |
CVE-2021-39232HIGH In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins. | Nov 19, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-45106HIGH Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user | Dec 3, 2024 | 8.1 | 23 | NO | NO |
CVE-2021-39234MEDIUM In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security c | Nov 19, 2021 | 6.8 | 23 | NO | NO |
CVE-2021-39235MEDIUM In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation | Nov 19, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-41532MEDIUM In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints. | Nov 19, 2021 | 5.3 | 20 | NO | NO |
CVE-2020-17517HIGH The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets t | Apr 27, 2021 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Ozone
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.4.0 | 1 | 8.1 | 0.6% | 0 | 0 |