In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Ozone |
Apache |
* |
1.2.0 (excluding) |
References