[CONTROLLER-1355] [SECURITY] LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks CVE-2015-4000 Created: 03/Jun/15 Updated: 19/Oct/17 Resolved: 17/Nov/15 |
|
| Status: | Resolved |
| Project: | controller |
| Component/s: | karaf |
| Affects Version/s: | Beryllium |
| Fix Version/s: | None |
| Type: | Bug | ||
| Reporter: | David Jorm | Assignee: | Unassigned |
| Resolution: | Done | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Environment: |
Operating System: All |
||
| Issue Links: |
|
||||||||
| External issue ID: | 3553 | ||||||||
| Priority: | Normal | ||||||||
| Description |
|
Various components of OpenDaylight are affected by the LOGJAM TLS downgrade vulnerability: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4000 |
| Comments |
| Comment by Colin Dixon [ 09/Jun/15 ] |
|
For more information see BUG3552. |
| Comment by Ryan Goulding [ 17/Nov/15 ] |