SQL Injection Vulnerability in OpenDaylight AAA Component
CVE-2022-45930
7.5HIGH
Summary
A SQL injection vulnerability was identified in the OpenDaylight AAA component, specifically targeting the deleteDomain function within the DomainStore class. This flaw impacts versions prior to 0.16.5 and affects the /auth/v1/domains/ API interface, potentially allowing attackers to manipulate database queries, leading to unauthorized data access and modifications. It is crucial for users operating affected versions to apply security updates promptly to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved