Maven package
io.atomix/atomix
pkg:maven/io.atomix/atomix
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-35216 | Med | 5.9 | <= 3.1.5 | — | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages. | |
| CVE-2020-35215 | Med | 6.5 | <= 3.1.5 | — | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states. | |
| CVE-2020-35214 | Hig | 8.1 | <= 3.1.5 | — | Dec 16, 2021 | An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations. | |
| CVE-2020-35213 | Hig | 8.1 | <= 3.1.5 | — | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node. | |
| CVE-2020-35211 | Hig | 7.5 | <= 3.1.5 | — | Dec 16, 2021 | An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext. | |
| CVE-2020-35210 | Med | 6.5 | <= 3.1.5 | — | Dec 16, 2021 | A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft OpenSessionRequest messages. | |
| CVE-2020-35209 | Hig | 7.5 | <= 3.1.5 | — | Dec 16, 2021 | An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information. |
- affected <= 3.1.5
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.
- affected <= 3.1.5
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.
- affected <= 3.1.5
An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations.
- affected <= 3.1.5
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.
- affected <= 3.1.5
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.
- affected <= 3.1.5
A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft OpenSessionRequest messages.
- affected <= 3.1.5
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.