From 7fca6eedf4d67baa85fb2f112f421559c94eb73c Mon Sep 17 00:00:00 2001 From: Krzysztof Opasiak Date: Wed, 5 Jun 2019 02:08:05 +0200 Subject: Document OJSI-77 (CVE-2019-12116) vulnerability Issue-ID: OJSI-77 Signed-off-by: Krzysztof Opasiak Change-Id: I4a1f92491cc0792659493cecc73575aba4100116 --- docs/release-notes.rst | 1 + 1 file changed, 1 insertion(+) (limited to 'docs/release-notes.rst') diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 1cdd7f4a43..84947c6f83 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -103,6 +103,7 @@ Security Notes - [`OJSI-31 `__\ ] - Unsecured Swagger UI Interface in sdc-wfd-be - CVE-2019-12115 [`OJSI-76 `__\ ] - demo-sdc-sdc-be exposes JDWP on port 4000 which allows for arbitrary code execution +- CVE-2019-12116 [`OJSI-77 `__\ ] - demo-sdc-sdc-fe exposes JDWP on port 6000 which allows for arbitrary code execution *Known Vulnerabilities in Used Modules* -- cgit 1.2.3-korg