X-Git-Url: https://gerrit.onap.org/r/gitweb?a=blobdiff_plain;f=docs%2Frelease-notes.rst;h=0881dc7a8511b001290e479ea4e1802088bfbd14;hb=d0225b324afd683c4ae2037c4a017552cb457093;hp=fa838686957f61dd80d77b37bdd76819e12749e0;hpb=32f2b4995aed6c5515d2961faabd557a68b273b8;p=sdnc%2Foam.git diff --git a/docs/release-notes.rst b/docs/release-notes.rst index fa838686..0881dc7a 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -46,9 +46,17 @@ The full list of known issues in SDNC may be found in the ONAP Jira at `_ SDNC service allows for arbitrary code execution in sla/printAsGv form Fixed temporarily by disabling admportal +- `OJSI-91 `_ SDNC exposes unprotected API for user creation + Fixed temporarily by disabling admportal +- `OJSI-98 `_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster. + Fixed temporarily by disabling admportal +- CVE-2019-12112 `OJSI-199 `_ SDNC service allows for arbitrary code execution in sla/upload form + Fixed temporarily by disabling admportal *Known Security Issues* +- `OJSI-34 `_ Multiple SQL Injection issues in SDNC + *Known Vulnerabilities in Used Modules* Quick Links: