Known Vulnerabilities for products from Onosproject
Listed below are 13 of the newest known vulnerabilities associated with the vendor "Onosproject".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-30093 json | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers ... | 6.1 - MEDIUM | 2023-05-04 | 2023-05-12 |
| CVE-2019-13624 json | In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters wit... | 9.8 - CRITICAL | 2019-07-17 | 2019-07-19 |
| CVE-2018-1000616 json | ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\... | 9.8 - CRITICAL | 2018-07-09 | 2018-09-04 |
| CVE-2018-1000615 json | ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component... | 7.5 - HIGH | 2018-07-09 | 2020-08-24 |
| CVE-2018-1000614 json | ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm... | 9.8 - CRITICAL | 2018-07-09 | 2018-09-04 |
| CVE-2018-12691 json | Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.1... | 6.8 - MEDIUM | 2018-07-05 | 2018-09-04 |
| CVE-2017-1000081 json | Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution... | Not Provided | 2017-07-17 | 2025-04-20 |
| CVE-2017-1000080 json | Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets. | Not Provided | 2017-07-17 | 2025-04-20 |
| CVE-2017-1000079 json | Linux foundation ONOS 1.9.0 is vulnerable to a DoS. | Not Provided | 2017-07-17 | 2025-04-20 |
| CVE-2017-1000078 json | Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration | Not Provided | 2017-07-17 | 2025-04-20 |
| CVE-2017-13763 json | ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited. | 7.5 - HIGH | 2017-08-30 | 2019-10-03 |
| CVE-2017-13762 json | ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS. | 6.1 - MEDIUM | 2017-08-30 | 2017-09-01 |
| CVE-2015-7516 json | ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and ... | 7.5 - HIGH | 2017-08-24 | 2017-08-30 |
Known software with vulnerabilities from Onosproject
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Onosproject | Onos | 1.0.0 |