Ozone S3 Gateway allows bucket and key access to non authenticated users
Vulnerability Description
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to buckets and keys thereby exposing data to anonymous clients or users. This affected Apache Ozone prior to the 1.1.0 release.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-17517
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Apache Ozone would like to thank Kota Uenishi for reporting this issue.
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →