6.1
CVSSv3

CVE-2023-30093

Published: 04/05/2023 Updated: 12/05/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

onosproject onos

Github Repositories

My experiments in weaponizing ONOS applications (https://github.com/opennetworkinglab/onos)

Offensive ONOS My experiments in weaponizing ONOS applications This is a part of research activity for my Cybersecurity MSc Thesis (link), focused on detection of Cross App Poisoning Attacks in Software Defined Networks This research also led to discovery of CVE-2023-24279 and CVE-2023-30093 Useful papers to get context: Cross-App Poisoning in Software-Defined Networking

Proposal and Investigation of a framework for Cross App Poisoning attacks detection in Software Defined Networks - Master of Science in Cybersecurity Thesis, Sapienza University

Proposal and Investigation of a framework for Cross App Poisoning attacks detection in Software Defined Networks The thesis work led to discovery of CVE-2023-24279 and CVE-2023-30093 See also: the Paper "Cross App Poisoning Attacks Detection in Software Defined Networks" by Edoardo Ottavianelli and Marco Polverini edoardottt/offensive-onos (part of researc

My experiments in weaponizing ONOS applications (https://github.com/opennetworkinglab/onos)

Offensive ONOS My experiments in weaponizing ONOS applications This is a part of research activity for my Cybersecurity MSc Thesis (link), focused on detection of Cross App Poisoning Attacks in Software Defined Networks This research also led to discovery of CVE-2023-24279 and CVE-2023-30093 Useful papers to get context: Cross-App Poisoning in Software-Defined Networking