CVE-2019-1010234: Input Validation
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010234?
CVE-2019-1010234 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2019-1010234?
To fix CVE-2019-1010234, update to the latest version of ONOS that addresses this vulnerability.
What systems are impacted by CVE-2019-1010234?
CVE-2019-1010234 impacts ONOS versions 1.15.0 and earlier.
What kind of attack is possible with CVE-2019-1010234?
CVE-2019-1010234 allows an attacker to remotely execute arbitrary commands by sending a malicious HTTP request to the controller.
Who is affected by CVE-2019-1010234?
Organizations using the Linux Foundation ONOS versions 1.15.0 and earlier are affected by CVE-2019-1010234.