Описание
OpenDaylight SFC Allows Unauthorized Privileged Execution via Crafted Request
An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.
Пакеты
Наименование
org.opendaylight.sfc:sfc-parent
maven
Затронутые версииВерсия исправления
<= 0.10.4
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
11 месяцев назад
An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.