{"id":"CVE-2017-1000406","aliases":[],"url":"https://o3.security/vulnerability/CVE-2017-1000406","summary":"Password change doesn't result in Karaf clearing cache","details":"OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).","published":"2022-05-17T00:12:25Z","modified":"2024-12-08T05:34:29.986693Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.opendaylight.integration:distribution-karaf","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000406"},{"type":"PACKAGE","url":"https://git.opendaylight.org/gerrit"},{"type":"WEB","url":"https://git.opendaylight.org/gerrit/#/q/topic:AAA-151"},{"type":"WEB","url":"https://jira.opendaylight.org/browse/AAA-151"},{"type":"WEB","url":"http://seclists.org/oss-sec/2017/q4/320"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-08T05:34:29.986693Z"}}