CRITICAL 9.8 Maven
Opendaylight will authenticate any username and password combination
GHSA-qm24-4869-99pj · CVE-2015-1778
Published · Modified
Description
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-1778
- WEB https://web.archive.org/web/20150510044305/https://git.opendaylight.org/gerrit/#/c/16307
- WEB https://web.archive.org/web/20150510044305/https://wiki.opendaylight.org/view/Security_Advisories#.5BImportant.5D_CVE-2015-1778_OpenDaylight:_authentication_bypass
- PACKAGE github.com/opendaylight/odlparent
- WEB http://www.openwall.com/lists/oss-security/2015/03/20/3
Ready to move
Start Securing
Free, no credit card | First findings in minutes