2.2.0
4 years ago
1 months ago
Known vulnerabilities in the org.apache.ozone:ozone-main package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Improper Authentication via the download of metadata internal to the Storage Container Manager service. An attacker can obtain metadata without proper authentication. Note: This issue does not allow the attacker to modify the Ozone Storage Container Manager service or access sensitive information that could be exploited further, nor does it enable access to actual user data. How to fix Improper Authentication? Upgrade | [1.2.0,1.4.0) |