Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46hr-3cq3-mcgp

Опубликовано: 16 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

Пакеты

Наименование

org.opendaylight.aaa:aaa-artifacts

maven
Затронутые версииВерсия исправления

<= 0.19.3

Отсутствует

EPSS

Процентиль: 50%
0.00268
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-285
CWE-287
CWE-520

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

EPSS

Процентиль: 50%
0.00268
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-285
CWE-287
CWE-520