First published: Tue Jun 27 2017(Updated: )
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenDaylight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1778 is classified as a critical vulnerability due to its ability to allow unauthorized access to the system.
To fix CVE-2015-1778, update to Opendaylight Helium SR3 or later, as these versions address the authentication issue.
CVE-2015-1778 affects all versions of Opendaylight prior to Helium SR3.
CVE-2015-1778 poses a significant risk as it allows attackers to authenticate with any username and password, compromising the entire system.
You can determine if your installation is vulnerable by checking the version of Opendaylight you are using and confirming if it is prior to Helium SR3.