{"id":"GHSA-4px2-gqhv-mrc7","summary":"Password change doesn't result in Karaf clearing cache","details":"OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).","aliases":["CVE-2017-1000406"],"modified":"2024-12-08T05:34:29.986693Z","published":"2022-05-17T00:12:25Z","database_specific":{"github_reviewed_at":"2023-12-21T20:19:38Z","nvd_published_at":"2017-11-30T21:29:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000406"},{"type":"PACKAGE","url":"https://git.opendaylight.org/gerrit"},{"type":"WEB","url":"https://git.opendaylight.org/gerrit/#/q/topic:AAA-151"},{"type":"WEB","url":"https://jira.opendaylight.org/browse/AAA-151"},{"type":"WEB","url":"http://seclists.org/oss-sec/2017/q4/320"}],"affected":[{"package":{"name":"org.opendaylight.integration:distribution-karaf","ecosystem":"Maven","purl":"pkg:maven/org.opendaylight.integration/distribution-karaf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.6.4-Carbon"}]}],"versions":["0.2.0-Helium","0.2.1-Helium-SR1","0.2.1-Helium-SR1.1","0.2.2-Helium-SR2","0.2.3-Helium-SR3","0.2.4-Helium-SR4","0.3.0-Lithium","0.3.1-Lithium-SR1","0.3.2-Lithium-SR2","0.3.3-Lithium-SR3","0.3.4-Lithium-SR4","0.4.0-Beryllium","0.4.1-Beryllium-SR1","0.4.2-Beryllium-SR2","0.4.3-Beryllium-SR3","0.4.4-Beryllium-SR4","0.5.0-Boron","0.5.1-Boron-SR1","0.5.2-Boron-SR2","0.5.3-Boron-SR3","0.5.4-Boron-SR4","0.6.0-Carbon","0.6.1-Carbon","0.6.2-Carbon","0.6.3-Carbon","0.6.4-Carbon"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4px2-gqhv-mrc7/GHSA-4px2-gqhv-mrc7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}