CVE-2019-12131

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2020
Last modified:
20/03/2020

Description

An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:onap:open_network_automation_platform:*:*:*:*:*:*:*:* 3.0.0 (including) 4.0.0 (excluding)


References to Advisories, Solutions, and Tools