An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
Allowing a .NET application to run at potentially escalated levels of access to the underlying operating and file systems can be dangerous and result in various forms of attacks.
Link | Tags |
---|---|
https://doi.org/10.48550/arXiv.2408.16940 | technical description |
https://lf-opendaylight.atlassian.net/browse/AAA-285 | vendor advisory issue tracking |
https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html | release notes |