Improper Input Validation in ONOS SDN Controller by The Linux Foundation
CVE-2019-1010245
9.8CRITICAL
What is CVE-2019-1010245?
The ONOS SDN Controller, developed by The Linux Foundation, suffers from a vulnerability due to improper input validation in the YangLiveCompilerManager component. This flaw allows remote attackers to execute arbitrary commands on the controller through network connectivity. It is crucial for users of affected versions to upgrade to the fixed version 1.15 to mitigate this risk and enhance system security. Comprehensive knowledge of the underlying code, specifically in the apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java file, is essential for addressing this issue.
Affected Version(s)
ONOS SDN Controller 1.15 and earlier versions [fixed: 1.15]