SQL Injection Vulnerability in OpenDaylight AAA Component
CVE-2022-45930

7.5HIGH

Key Information:

Vendor
Linux
Vendor
CVE Published:
27 November 2022

Summary

A SQL injection vulnerability was identified in the OpenDaylight AAA component, specifically targeting the deleteDomain function within the DomainStore class. This flaw impacts versions prior to 0.16.5 and affects the /auth/v1/domains/ API interface, potentially allowing attackers to manipulate database queries, leading to unauthorized data access and modifications. It is crucial for users operating affected versions to apply security updates promptly to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.