Description
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.
Remediation
References
https://docs.google.com/presentation/d/1pRRLfdSUqUZ688CZ9e9AyceuXPGp9oyGj7j4bdSsBcw/edit?usp=sharing
Related Vulnerabilities
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2012-0803 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2017-5617 Vulnerability in maven package com.metsci.ext.com.kitfox.svg:svg-salamander
CVE-2019-19919 Vulnerability in maven package org.webjars.bower:handlebars
CVE-2020-14966 Vulnerability in maven package org.webjars.npm:jsrsasign