SQL Injection Vulnerability in OpenDaylight AAA Component
CVE-2022-45930
7.5HIGH
What is CVE-2022-45930?
A SQL injection vulnerability was identified in the OpenDaylight AAA component, specifically targeting the deleteDomain function within the DomainStore class. This flaw impacts versions prior to 0.16.5 and affects the /auth/v1/domains/ API interface, potentially allowing attackers to manipulate database queries, leading to unauthorized data access and modifications. It is crucial for users operating affected versions to apply security updates promptly to mitigate risks associated with this vulnerability.