From 9efc5e6ea56013249cb7d9746fa0b21916e79549 Mon Sep 17 00:00:00 2001 From: Krzysztof Opasiak Date: Wed, 5 Jun 2019 23:31:54 +0200 Subject: Document OJSI-95 vulnerability Issue-ID: OJSI-95 Signed-off-by: Krzysztof Opasiak Change-Id: Ica05a626601673f672cc0be6a8c6cdcbe94323f8 --- docs/release-notes.rst | 1 + 1 file changed, 1 insertion(+) (limited to 'docs') diff --git a/docs/release-notes.rst b/docs/release-notes.rst index fa09a4e31..4123ff95c 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -118,6 +118,7 @@ The Dublin release added the following functionality: - CVE-2019-12316 `OJSI-25 `_ - SQL Injection in APPC - `OJSI-29 `_ - Unsecured Swagger UI Interface in AAPC - CVE-2019-12124 `OJSI-63 `_ - APPC exposes Jolokia Interface which allows to read and overwrite any arbitrary file + - `OJSI-95 `_ - appc-cdt allows to impersonate any user by setting USER_ID *Known Vulnerabilities in Used Modules* -- cgit 1.2.3-korg