OpenDaylight Helium CVE-2015-1778 Authentication Bypass Vulnerability
BID:73255
Info
OpenDaylight Helium CVE-2015-1778 Authentication Bypass Vulnerability
| Bugtraq ID: | 73255 |
| Class: | Design Error |
| CVE: |
CVE-2015-1778 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2015 12:00AM |
| Updated: | Mar 20 2015 12:00AM |
| Credit: | Flavio Fernandes of Red Hat |
| Vulnerable: |
Opendaylight Helium 0 |
| Not Vulnerable: |
Opendaylight Helium SR3 |
Discussion
OpenDaylight Helium CVE-2015-1778 Authentication Bypass Vulnerability
OpenDaylight Helium is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
OpenDaylight Helium is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Exploit / POC
OpenDaylight Helium CVE-2015-1778 Authentication Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenDaylight Helium CVE-2015-1778 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenDaylight Helium CVE-2015-1778 Authentication Bypass Vulnerability
References:
References:
- OpenDaylight Home Page (OpenDaylight)
- OpenDaylight Security Advisories (https://wiki.opendaylight.org/view/Security_Advisories)
- Switched from the WIP custom authn realm to using tomcat-users.xml (OpenDaylight)