First published: Thu Nov 30 2017(Updated: )
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.opendaylight.integration:distribution-karaf | <=0.6.4-Carbon | |
OpenDaylight | =0.6.1-carbon |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000406 is considered to have a medium severity due to the risk of unauthorized access with the old password.
To fix CVE-2017-1000406, manually clear the Karaf cache by restarting the service after a password change.
CVE-2017-1000406 affects OpenDaylight Karaf versions up to and including 0.6.4-Carbon.
Yes, the old password can be used until the Karaf cache is manually cleared after a password change.
The vulnerability in CVE-2017-1000406 is a cache management issue that fails to update the user's password in the system.