Time of Check Time of Use (TOCTOU) Affecting org.onosproject:onos-apps-acl package, versions [,1.13.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
0.07% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGONOSPROJECT-32423
  • published19 Jul 2018
  • disclosed22 Jun 2018
  • creditBenjamin E. Ujcich

Introduced: 22 Jun 2018

CVE-2018-12691  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade org.onosproject:onos-apps-acl to version 1.13.2 or higher.

Overview

org.onosproject:onos-apps-acl is a SDN controller platform that supports the transition from legacy “brown field” networks to SDN “green field” networks.

Affected versions of this package are vulnerable to Time of Check Time of Use (TOCTOU). An attacker could bypass network access control via data plane packet injection.

CVSS Scores

version 3.1