Description
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.
Remediation
References
https://docs.google.com/presentation/d/1pRRLfdSUqUZ688CZ9e9AyceuXPGp9oyGj7j4bdSsBcw/edit?usp=sharing
Related Vulnerabilities
CVE-2022-25844 Vulnerability in npm package angular
CVE-2021-21627 Vulnerability in maven package org.jenkins-ci.plugins:libvirt-slave
CVE-2016-10555 Vulnerability in npm package jwt-simple
CVE-2022-2932 Vulnerability in npm package mobiledoc-dom-renderer
CVE-2019-1003050 Vulnerability in maven package org.jenkins-ci.main:jenkins-core