GHSA-c6p7-vhw7-rc9w
Dashboard / Vulnerabilities / GHSA-c6p7-vhw7-rc9w
Summary: ONOS vulnerable to denial of service due to unrestricted NettyMessagingManager payload
Details: Open Network Operating System, ONOS, versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated because the NettyMessagingManager payload size is not limited. ONOS nodes timeout when trying to connect to the cluster in vm test cluster, leading to a potential denial of service.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-13763, https://github.com/opennetworkinglab/onos/commit/f7c7f6f229978fe4e78045069a4485504cc108c4, https://gerrit.onosproject.org/#/c/13831, https://gerrit.onosproject.org/#/c/14318, https://github.com/opennetworkinglab/onos, https://jira.onosproject.org/browse/ONOS-6401
Affected packages
Package
Name: org.onosproject:onos-base
Purl: pkg:maven/org.onosproject/onos-base
Affected ranges
Type: ECOSYSTEM
Events:
