From 07fa58704137516119b3e3cddcebc4f9599b20ab Mon Sep 17 00:00:00 2001 From: Krzysztof Opasiak Date: Thu, 30 May 2019 17:40:07 +0200 Subject: Document OJSI-28 vulnerability Issue-ID: OJSI-28 Signed-off-by: Krzysztof Opasiak Change-Id: I0d1a1ca7975349f129db021883ea4ac726d2bf6f --- docs/sections/release-notes.rst | 1 + 1 file changed, 1 insertion(+) (limited to 'docs/sections') diff --git a/docs/sections/release-notes.rst b/docs/sections/release-notes.rst index 936470d0..0c6d86d5 100644 --- a/docs/sections/release-notes.rst +++ b/docs/sections/release-notes.rst @@ -105,6 +105,7 @@ Source code of DCAE components are released under the following repositories on *Known Security Issues* + * Unsecured Swagger UI Interface in xdcae-datafile-collector. [`OJSI-28 `_] * In default deployment DCAEGEN2 (xdcae-datafile-collector) exposes HTTP port 30223 outside of cluster. [`OJSI-109 `_] * In default deployment DCAEGEN2 (xdcae-ves-collector) exposes HTTP port 30235 outside of cluster. [`OJSI-116 `_] * In default deployment DCAEGEN2 (dcae-datafile-collector) exposes HTTP port 30262 outside of cluster. [`OJSI-131 `_] -- cgit 1.2.3-korg