AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-45106

HIGH · CVSS 8.1 EPSS 0.56%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-12-03 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It affects Apache.

CVE
CVE-2024-45106
Severity
HIGH
CVSS
8.1
EPSS
0.56%
Apache

Original NVD Description

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. The default value of this configuration is false. * The user configured in ozone.s3g.kerberos.principal is also configured in ozone.s3.administrators or ozone.administrators. Users are recommended to upgrade to Apache Ozone version 1.4.1 which disables the affected endpoint.

Related CVEs

Other vulnerabilities affecting the same vendor(s)