Feed/CVE-2015-1778
CVE-2015-1778CRITICALCVSS 9.8

Opendaylight will authenticate any username and password combination

Published May 17, 2022·Updated Jun 30, 2026

NVD Description

The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.

Affected Packages (1)

org.opendaylight.odlparent:opendaylight-karaf-resourcesMAVEN
Fixed in 0.2.3-Helium-SR3

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free