CVE-2017-1000406: Opendaylight Karaf
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Affected products
- Opendaylight Karaf: version 0.6.1-carbon only
Published 2017-11-30. Last modified 2026-06-17.