Description:

Authenticated users knowing the ID of an existing block can craft specific 
request allowing access those blocks, bypassing other security checks like ACL. 

This issue is being tracked as HDDS-5061

Mitigation:

Upgrade to Apache Ozone release version 1.2.0

Credit:

Apache Ozone would like to thank Marton Elek for reporting this issue.


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@ozone.apache.org
For additional commands, e-mail: dev-h...@ozone.apache.org

Reply via email to