summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorKrzysztof Opasiak <k.opasiak@samsung.com>2019-06-06 01:28:19 +0200
committerKrzysztof Opasiak <k.opasiak@samsung.com>2019-06-06 01:28:19 +0200
commita7b9337e3691f89d0b3f7e36ab73ef964476a655 (patch)
treec3cf04eb28f19ea14a6f02e42701f5b59b0dd902
parentebc8379659a23fb28cdf200bb653cf92ab606c0f (diff)
Document OJSI-199 (CVE-2019-12112) vulnerability
Issue-ID: OJSI-199 Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com> Change-Id: I0cf61765fcab7fac5834d697004872e5bc58479c Former-commit-id: b3fd8af2a5e1b4de6ec194a4ef7b0b6511808c0f
-rw-r--r--docs/release-notes.rst2
1 files changed, 2 insertions, 0 deletions
diff --git a/docs/release-notes.rst b/docs/release-notes.rst
index 67034c6b..56443f1b 100644
--- a/docs/release-notes.rst
+++ b/docs/release-notes.rst
@@ -50,6 +50,8 @@ The full list of known issues in SDNC may be found in the ONAP Jira at <https://
Fixed temporarily by disabling admportal
- `OJSI-98 <https://jira.onap.org/browse/OJSI-98>`_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster.
Fixed temporarily by disabling admportal
+- CVE-2019-12112 `OJSI-199 <https://jira.onap.org/browse/OJSI-199>`_ SDNC service allows for arbitrary code execution in sla/upload form
+ Fixed temporarily by disabling admportal
*Known Security Issues*