High severity8.8NVD Advisory· Published Nov 19, 2021· Updated Jun 17, 2026
CVE-2021-39236
CVE-2021-39236
Description
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.hadoop:hadoop-ozone-ozone-managerMaven | < 1.2.0 | 1.2.0 |
Affected products
2- Apache Software Foundation/Apache Ozonev5Range: 1.0
Patches
Vulnerability mechanics
References
8- issues.apache.org/jira/browse/HDDS-4763nvdExploitWEB
- www.openwall.com/lists/oss-security/2021/11/19/7nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-5993-wwpg-m92cghsaADVISORY
- mail-archives.apache.org/mod_mbox/ozone-dev/202111.mbox/%3C0fd74baa-88a0-39a2-8f3a-b982acb25d5a%40apache.org%3EnvdMailing ListMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-39236ghsaADVISORY
- github.com/apache/ozone/commit/60e078729e18ef1be276f35659957ac553d266f7ghsaWEB
- github.com/apache/ozone/pull/1871ghsaWEB
- lists.apache.org/thread/q0lhspolnwfbsw33w98b7b1923n1np4dghsaWEB
News mentions
0No linked articles in our index yet.