summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorKrzysztof Opasiak <k.opasiak@samsung.com>2019-06-06 01:01:02 +0200
committerKrzysztof Opasiak <k.opasiak@samsung.com>2019-06-06 01:22:59 +0200
commitf52d6888f342a8f4206823f141dc00d4227cf73b (patch)
tree249c3bbabb488b0c4702818002b3746f8b1d8925
parentf114f3be79ef1553a1df42c132b1c859ab689ed2 (diff)
Document OJSI-41 (CVE-2019-12132) vulnerability
Issue-ID: OJSI-41 Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com> Change-Id: I9d80043c3f8dc9d2f30d178b34e11ff1d0c366ea Former-commit-id: e02a73b130b8caa37dde3c0d824492246bf24447
-rw-r--r--docs/release-notes.rst5
1 files changed, 3 insertions, 2 deletions
diff --git a/docs/release-notes.rst b/docs/release-notes.rst
index f4ea951a..40192add 100644
--- a/docs/release-notes.rst
+++ b/docs/release-notes.rst
@@ -40,6 +40,9 @@ The full list of known issues in SDNC may be found in the ONAP Jira at <https://
*Fixed Security Issues*
+- CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
+ Fixed temporarily by disabling admportal
+
*Known Security Issues*
*Known Vulnerabilities in Used Modules*
@@ -240,5 +243,3 @@ in release 1.2.1:
**Other**
NA
-
-