Uploaded image for project: 'ONAP JIRA Security Issues'
  1. ONAP JIRA Security Issues
  2. OJSI-79

demo-sdc-sdc-wfd-be exposes JDWP on port 7001 which allows for arbitrary code execution (CVE-2019-12118)

CloneClone+Clone++
    XMLWordPrintable

Details

    • CVE-2019-12118
    • OJSI-SDC

    Description

      Impact description (draft)

      Title: SDC  exposes JDWP outside of pod which allows for arbitrary code execution

      Reporter: Radosław Żeszczuk from Samsung

      Products: SDC

      Affects: Dublin and earlier

      Description:

      Radosław Żeszczuk from Samsung reported vulnerability in SDC. By accessing port 7001 of  demo-sdc-sdc-wfd-be pod an unauthenticated attacker who already has access to pod to pod communication may execute arbitrary code inside those pods. All OOM ONAP setups which includes SDC are affected.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            rob.bog Robert Bogacki
            r.z . .
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: