OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://git.opendaylight.org/gerrit/#/q/topic:AAA-151 | vendor advisory |
https://jira.opendaylight.org/browse/AAA-151 | vendor advisory issue tracking |
http://seclists.org/oss-sec/2017/q4/320 | third party advisory mailing list |