X-Git-Url: https://gerrit.onap.org/r/gitweb?a=blobdiff_plain;ds=sidebyside;f=docs%2Frelease-notes.rst;h=d7d6b1710aae249a55060d86ab6d9a54940927db;hb=067574bb755a0f11c8f982fe5f20e164858aaef5;hp=bdafa1cb2cdcacba2f17517bf83f559bffd7af7b;hpb=40bd3f09e43fa80097268230b5432e7a55b8b715;p=sdnc%2Foam.git diff --git a/docs/release-notes.rst b/docs/release-notes.rst index bdafa1cb..d7d6b171 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -44,9 +44,21 @@ The full list of known issues in SDNC may be found in the ONAP Jira at `_ SDNC service allows for arbitrary code execution in sla/printAsXml form Fixed temporarily by disabling admportal +- CVE-2019-12113 `OJSI-43 `_ SDNC service allows for arbitrary code execution in sla/printAsGv form + Fixed temporarily by disabling admportal +- `OJSI-91 `_ SDNC exposes unprotected API for user creation + Fixed temporarily by disabling admportal +- `OJSI-98 `_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster. + Fixed temporarily by disabling admportal +- CVE-2019-12112 `OJSI-199 `_ SDNC service allows for arbitrary code execution in sla/upload form + Fixed temporarily by disabling admportal *Known Security Issues* +- `OJSI-34 `_ Multiple SQL Injection issues in SDNC +- `OJSI-99 `_ In default deployment SDNC (sdnc) exposes HTTP port 30202 outside of cluster. +- `OJSI-100 `_ In default deployment SDNC (sdnc-dgbuilder) exposes HTTP port 30203 outside of cluster. + *Known Vulnerabilities in Used Modules* Quick Links: