The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/03/20/3 | vdb entry mailing list |
http://www.securityfocus.com/bid/73255 | vdb entry third party advisory |
https://wiki.opendaylight.org/view/Security_Advisories | patch vendor advisory |
https://cloudrouter.org/security/ | third party advisory |