First published: Thu Sep 30 2021(Updated: )
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Floodlight | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-18683 is a vulnerability in Floodlight versions up to and including 1.2 that allows for poor input validation in the checkFlow function, leading to mishandling of undefined fields.
CVE-2020-18683 has a severity rating of 9.8, which is considered critical.
Atlassian Floodlight versions up to and including 1.2 are affected by CVE-2020-18683.
To fix CVE-2020-18683, it is recommended to update to a fixed version of Floodlight that addresses the poor input validation issue.
More information about CVE-2020-18683 can be found at the following reference link: [https://drive.google.com/open?id=15I75JBmFYB9rLm9ZvcFtjHy0e2a-9lyO](https://drive.google.com/open?id=15I75JBmFYB9rLm9ZvcFtjHy0e2a-9lyO)