ONOS vulnerable to denial of service due to unrestricted NettyMessagingManager payload
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 10, 2023
Package
Affected versions
>= 1.8.0, <= 1.10.0
Patched versions
1.11.0
Description
Published by the National Vulnerability Database
Aug 30, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 26, 2023
Last updated
Oct 10, 2023
Open Network Operating System, ONOS, versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated because the NettyMessagingManager payload size is not limited. ONOS nodes timeout when trying to connect to the cluster in vm test cluster, leading to a potential denial of service.
References