CVE-2015-1778: Critical severity Opendaylight OpenDaylight vulnerability
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1778?
CVE-2015-1778 is classified as a critical vulnerability due to its ability to allow unauthorized access to the system.
How do I fix CVE-2015-1778?
To fix CVE-2015-1778, update to Opendaylight Helium SR3 or later, as these versions address the authentication issue.
What systems are affected by CVE-2015-1778?
CVE-2015-1778 affects all versions of Opendaylight prior to Helium SR3.
What risks does CVE-2015-1778 pose?
CVE-2015-1778 poses a significant risk as it allows attackers to authenticate with any username and password, compromising the entire system.
How can I determine if my installation is vulnerable to CVE-2015-1778?
You can determine if your installation is vulnerable by checking the version of Opendaylight you are using and confirming if it is prior to Helium SR3.