[MAVEN:GHSA-G7P8-R2CH-4RMF] Malicious Atomix node queries expose sensitive information

Severity Moderate
Affected Packages 1
CVEs 1

An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.

Package Affected Version
pkg:maven/io.atomix/atomix <= 3.1.5
ID
MAVEN:GHSA-G7P8-R2CH-4RMF
Severity
moderate
URL
https://github.com/advisories/GHSA-g7p8-r2ch-4rmf
Published
2021-12-17T20:41:45
(2 years ago)
Modified
2023-02-01T05:07:07
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.atomix/atomix io.atomix atomix <= 3.1.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...