aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDan Timoney <dtimoney@att.com>2019-06-07 02:11:19 +0000
committerGerrit Code Review <gerrit@onap.org>2019-06-07 02:11:19 +0000
commit2e6c39d128f675739bc6359301a653e1a1985f58 (patch)
tree785f226cffe6fd979e818bb5caf29a552270f64d
parent3bb7991c162ab7fa0350ae0cbce93db464db8f37 (diff)
parentf52d6888f342a8f4206823f141dc00d4227cf73b (diff)
Merge "Document OJSI-41 (CVE-2019-12132) vulnerability"
Former-commit-id: cb7bffceb87ca03c4055dbbe1c74e830670ddf79
-rw-r--r--docs/release-notes.rst5
1 files changed, 3 insertions, 2 deletions
diff --git a/docs/release-notes.rst b/docs/release-notes.rst
index f4ea951a..40192add 100644
--- a/docs/release-notes.rst
+++ b/docs/release-notes.rst
@@ -40,6 +40,9 @@ The full list of known issues in SDNC may be found in the ONAP Jira at <https://
*Fixed Security Issues*
+- CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
+ Fixed temporarily by disabling admportal
+
*Known Security Issues*
*Known Vulnerabilities in Used Modules*
@@ -240,5 +243,3 @@ in release 1.2.1:
**Other**
NA
-
-