VDB
Sign up
MEDIUM4.3

GHSA-46hr-3cq3-mcgp

OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability

Details

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.opendaylight.aaa:aaa-artifacts
Introduced in: 0

No fixed version published yet for org.opendaylight.aaa:aaa-artifacts (maven). Pin to a known-safe version or switch to an alternative.

References