CVE-2024-46943 Information

Description

An issue was discovered in OpenDaylight Authentication Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer even if this rogue controller does not possess the complete cluster configuration information.

Reference

https://doi.org/10.48550/arXiv.2408.16940 https://lf-opendaylight.atlassian.net/browse/AAA-285 https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html

Share on: