GHSA-f2x4-547g-rp95

Suggest an improvement
Source
https://github.com/advisories/GHSA-f2x4-547g-rp95
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f2x4-547g-rp95/GHSA-f2x4-547g-rp95.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f2x4-547g-rp95
Aliases
  • CVE-2015-1612
Published
2022-05-17T02:50:39Z
Modified
2025-04-22T18:12:15Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
OpenFlow plugin for OpenDaylight LLDP Relay
Details

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reuse of LLDP packets, aka "LLDP Relay."

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-22T17:32:34Z",
    "nvd_published_at": "2017-04-04T17:59:00Z",
    "severity": "HIGH"
}
References

Affected packages

Maven / org.opendaylight.openflowplugin:openflowplugin

Package

Name
org.opendaylight.openflowplugin:openflowplugin
View open source insights on deps.dev
Purl
pkg:maven/org.opendaylight.openflowplugin/openflowplugin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.6-Helium-SR3

Affected versions

0.*
0.0.1
0.0.2
0.0.3-Helium
0.0.4-Helium-SR1
0.0.4-Helium-SR1.1
0.0.5-Helium-SR2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f2x4-547g-rp95/GHSA-f2x4-547g-rp95.json"