The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java. The attack vector is: network connectivity. The fixed version is: 1.15.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://drive.google.com/open?id=1OkMtrMgjjINsDUQwxpGxjbATB6hiwqyv | third party advisory exploit |
https://gerrit.onosproject.org/#/c/20767/ | third party advisory patch |