PT-2024-32291 · Opendaylight · Opendaylight Md-Sal

Published

2024-09-15

·

Updated

2024-09-25

·

CVE-2024-46942

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) versions through 13.0.1
Description A controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.
Recommendations For OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) versions through 13.0.1, consider restricting the configuration capabilities of controllers with follower roles to prevent unauthorized flow entry configuration until a patch is available.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-46942
GHSA-HV38-H5PJ-C96J

Affected Products

Opendaylight Md-Sal