Description
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.
Affected products
- Apache Software Foundation / Apache OzoneEverglades (1.1.0) – 1.1.0