Input Validation Vulnerability in Floodlight Vendor's StaticFlowEntryPusherResource Java Component
CVE-2020-18683

9.8CRITICAL

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
30 September 2021

Summary

Floodlight, version 1.2, contains a significant input validation flaw within the StaticFlowEntryPusherResource.java component. This vulnerability arises from the mishandling of undefined fields in the checkFlow method. An attacker could exploit this weakness to manipulate the system's behavior leading to unintended effects on network management functionalities.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.