aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorosgn422w <gervais-martial.ngueko@intl.att.com>2019-06-04 15:32:39 +0200
committerosgn422w <gervais-martial.ngueko@intl.att.com>2019-06-04 15:32:39 +0200
commit20f2f6357dbff97aa4a085846150c230b399a478 (patch)
tree69bcbfe5b6d278e5b8eb9b497819e838717ecc9d
parent0591d6855ce589fe78c6360499a278b2ed2e6ccf (diff)
improve security
Improve security section of release notes Issue-ID: SECCOM-238 Change-Id: I8ab31bc1d759625781daeb45e1f6562d69ea6e9a Signed-off-by: osgn422w <gervais-martial.ngueko@intl.att.com>
-rw-r--r--docs/release-notes.rst10
1 files changed, 10 insertions, 0 deletions
diff --git a/docs/release-notes.rst b/docs/release-notes.rst
index e5305e0e..547c9655 100644
--- a/docs/release-notes.rst
+++ b/docs/release-notes.rst
@@ -32,6 +32,16 @@ The main goal of the Dublin release was to:
**Security Notes**
+*Fixed Security Issues*
+
+ - `OJSI-128 <https://jira.onap.org/browse/OJSI-128>`_ In default deployment CLAMP (clamp) exposes HTTP port 30258 outside of cluster.
+ - `OJSI-147 <https://jira.onap.org/browse/OJSI-147>`_ In default deployment CLAMP (cdash-kibana) exposes HTTP port 30290 outside of cluster.
+ - `OJSI-152 <https://jira.onap.org/browse/OJSI-152>`_ In default deployment CLAMP (clamp) exposes HTTP port 30295 outside of cluster.
+
+*Known Security Issues*
+
+*Known Vulnerabilities in Used Modules*
+
CLAMP code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and actions to be taken in future release.
The CLAMP open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=64003444>`_.