An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Authentication,_authorization_and_accounting | Opendaylight | * | 0.19.3 (including) |