HIGH
opendaylight: Previous password continues to work after password change
Published Nov 30, 2017
7.5
HIGHCVSS 3.0
EPSS 1.09%
Description
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Affected products
No data.
- 0.6.1-carbon
No data.
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Not affected
Red Hat OpenStack Platform 11 (Ocata)
opendaylight
Will not fix
Red Hat OpenStack Platform 12 (Pike)
opendaylight
Will not fix
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Affected
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://seclists.org/oss-sec/2017/q4/320 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000406 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1530424 Issue Tracking
- https://git.opendaylight.org/gerrit/#/q/topic:AAA-151 x_refsource_CONFIRMVendor Advisory
- https://github.com/advisories/GHSA-4px2-gqhv-mrc7 Advisory
- https://jira.opendaylight.org/browse/AAA-151 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000406
- https://www.cve.org/CVERecord?id=CVE-2017-1000406
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/oss-sec/2017/q4/320 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-1000406 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1530424 | Issue Tracking | |
| https://git.opendaylight.org/gerrit/#/q/topic:AAA-151 | x_refsource_CONFIRMVendor Advisory | |
| https://github.com/advisories/GHSA-4px2-gqhv-mrc7 | Advisory | |
| https://jira.opendaylight.org/browse/AAA-151 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000406 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000406 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 30, 2017
Updated Sep 16, 2024
Reserved Nov 30, 2017
Link CVE-2017-1000406
CISA Vulnrichment
GHSA-4PX2-GQHV-MRC7 Updated n/a