Description
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.
Remediation
References
https://docs.google.com/presentation/d/1pRRLfdSUqUZ688CZ9e9AyceuXPGp9oyGj7j4bdSsBcw/edit?usp=sharing
Related Vulnerabilities
CVE-2021-23416 Vulnerability in npm package curly-bracket-parser
CVE-2022-34112 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2021-39177 Vulnerability in maven package org.geysermc:connector
CVE-2022-25878 Vulnerability in npm package protobufjs
CVE-2022-2422 Vulnerability in npm package feathers-sequelize