The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://git.opendaylight.org/gerrit/#/c/17709/ | patch vendor advisory |
https://wiki.opendaylight.org/view/Security_Advisories | patch vendor advisory |
https://cloudrouter.org/security/ | broken link |