Ozone

Vendor:

First CVE: Apr 27, 2021 · Active for 5 years

11
Total CVEs
More Total CVEs than 89% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ozone over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2021
5 years ago
Most Recent CVE
Dec 3, 2024
598 days ago

CVE Severity & Scoring

Ozone11 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to th
Nov 19, 20219.831NONO
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.
Nov 19, 20219.129NONO
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
Nov 19, 20218.828NONO
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from
Nov 19, 20219.128NONO
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
Nov 19, 20218.827NONO
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user
Dec 3, 20248.123NONO
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security c
Nov 19, 20216.823NONO
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation
Nov 19, 20216.522NONO
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.
Nov 19, 20215.320NONO
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets t
Apr 27, 20217.520NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Ozone

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.4.018.10.6%00