X-Git-Url: https://gerrit.onap.org/r/gitweb?a=blobdiff_plain;f=docs%2Frelease-notes.rst;h=59e173444f0aa7d37fee16e33f36de9b6b79e184;hb=8886d15461f5003b7d81677570ee3f75946b1354;hp=7e2736d3a2d04df611ee06903a57af82d037edbc;hpb=9306dd8333497633a0c764998b0da528ead0ffef;p=portal.git diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 7e2736d3..59e17344 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -12,7 +12,7 @@ Version: 2.6.0 .. toctree:: :maxdepth: 1 -Maintanance release with bug fixes and security enhancements. +Maintenance release with bug fixes and security enhancements. **No New Features** @@ -31,7 +31,15 @@ Maintanance release with bug fixes and security enhancements. 4. Then demo user can access AAI UI app from Portal **Security Notes** - * Security Enhancements - Fixed OJSI issues. + +*Fixed Security Issues* + + * CVE-2019-12122 - ONAP Portal allows to retrieve password of currently active user [`OJSI-65 `_] + * CVE-2019-12121 - ONAP Portal is vulnerable for Padding Oracle attack [`OJSI-92 `_] + +*Known Security Issues* + +*Known Vulnerabilities in Used Modules* * Addressed security issues reported by NexusIQ Critical and Severe issues Quick Links: