CVE-2025-29315
CVE-2025-29315
9.8
CriticalPublished:
Last updated:
Source:cve@mitre.org
Deferred
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.
References
134c704f-9b21-4f2e-91b3-4a467353bcc0
https://blog.csdn.net/weixin_43959580/article/details/144794289