CVE-2019-1010234: Linuxfoundation Open Network Operating System
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity.
Affected products
- Linuxfoundation Open Network Operating System: up to and including 1.15.0
Published 2019-07-22. Last modified 2026-06-17.