The custom authentication realm used by karaf-tomcat’s “opendaylight” realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1778
Reference (s):
- BID:73255
- URL: http://www.securityfocus.com/bid/73255
- https://cloudrouter.org/security/
- https://wiki.opendaylight.org/view/Security_Advisories
- MLIST:[oss-security] 20150320 OpenDaylight security advisory: CVE-2015-1778 authentication bypass, CVE-2015-1611 CVE-2015-1612 topology spoofing via LLDP

