First published: Wed Feb 21 2018(Updated: )
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Floodlight | <1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6569 refers to a race condition vulnerability in the LoadBalancer module in the Atlassian Floodlight Controller before version 1.2.
The vulnerability allows remote attackers to cause a denial of service by exploiting the race condition, resulting in a NULL pointer dereference and thread crash.
Remote attackers can exploit the vulnerability by performing a state manipulation attack.
The severity of CVE-2015-6569 is medium, with a CVSS severity score of 5.9.
Update to Atlassian Floodlight Controller version 1.2 or later to fix the vulnerability.