First published: Mon Jul 22 2019(Updated: )
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1010234 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2019-1010234, update to the latest version of ONOS that addresses this vulnerability.
CVE-2019-1010234 impacts ONOS versions 1.15.0 and earlier.
CVE-2019-1010234 allows an attacker to remotely execute arbitrary commands by sending a malicious HTTP request to the controller.
Organizations using the Linux Foundation ONOS versions 1.15.0 and earlier are affected by CVE-2019-1010234.