Details
-
Task
-
Status: Public disclosure
-
Highest
-
Resolution: Done
-
Casablanca Maintenance Release, Dublin Release, Casablanca
-
CVE-2019-12126
-
OJSI-DCAEGEN2
Description
Impact description (draft)
Title: Unprotected APIs/UIs exposed in DCAE project
Reporter: Jakub Botwicz, Wojciech Rauner, Łukasz Wrochna and Radosław Żeszczuk from Samsung
Products: DCAE
Affects: Dublin and earlier
Description:
Jakub Botwicz, Wojciech Rauner, Łukasz Wrochna and Radosław Żeszczuk from Samsung reported a vulnerability in ONAP DCAE. By accessing port 32010, an attacker gains full access to the respective ONAP service without any authentication. All ONAP OOM setups are affected.
Attachments
Issue Links
- relates to
-
OJSI-161 xdcae-tca-analytics exposes plain text HTTP endpoint using port 32010
-
- Public disclosure
-
1.
|
Port 32010 exposes unprotected service outside of cluster |
|
Public disclosure | Vijay Venkatesh Kumar |