High severity7.5NVD Advisory· Published Nov 30, 2017· Updated May 13, 2026
CVE-2017-1000406
CVE-2017-1000406
Description
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opendaylight.integration:distribution-karafMaven | <= 0.6.4-Carbon | — |
Affected products
1- cpe:2.3:a:opendaylight:karaf:0.6.1-carbon:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- seclists.org/oss-sec/2017/q4/320nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-4px2-gqhv-mrc7ghsaADVISORY
- jira.opendaylight.org/browse/AAA-151nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-1000406ghsaADVISORY
News mentions
0No linked articles in our index yet.