Description
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.
Remediation
References
https://gerrit.onosproject.org/#/c/18867/
https://wiki.onosproject.org/display/ONOS/Security+advisories
Related Vulnerabilities
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15to18
CVE-2022-0122 Vulnerability in npm package node-forge
CVE-2020-28472 Vulnerability in maven package org.webjars.bower:aws-sdk
CVE-2020-11022 Vulnerability in maven package org.webjars.bower:jquery
CVE-2021-39154 Vulnerability in maven package com.thoughtworks.xstream:xstream