X-Git-Url: https://gerrit.onap.org/r/gitweb?a=blobdiff_plain;f=docs%2Frelease-notes.rst;h=67034c6b2931b52c47f625a270757424bb001de7;hb=a25e29ba185d4e4e337ea1cf9c8103b64dfdc737;hp=40192addf34544ac1ebc33d9a1e0367eac4b1b89;hpb=e02a73b130b8caa37dde3c0d824492246bf24447;p=sdnc%2Foam.git diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 40192add..67034c6b 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -42,6 +42,14 @@ The full list of known issues in SDNC may be found in the ONAP Jira at `_ SDNC service allows for arbitrary code execution in sla/dgUpload form Fixed temporarily by disabling admportal +- CVE-2019-12123 `OJSI-42 `_ SDNC service allows for arbitrary code execution in sla/printAsXml form + Fixed temporarily by disabling admportal +- CVE-2019-12113 `OJSI-43 `_ SDNC service allows for arbitrary code execution in sla/printAsGv form + Fixed temporarily by disabling admportal +- `OJSI-91 `_ SDNC exposes unprotected API for user creation + Fixed temporarily by disabling admportal +- `OJSI-98 `_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster. + Fixed temporarily by disabling admportal *Known Security Issues*