Document OJSI-205 (CVE-2019-12130) vulnerability 32/88932/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Thu, 30 May 2019 16:30:49 +0000 (18:30 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Thu, 30 May 2019 16:30:49 +0000 (18:30 +0200)
Issue-ID: OJSI-205
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: Icb0cd700c8c5fbffc2f9d26c20b506445df23296

docs/release-notes.rst

index 2abf324..fbc47c2 100644 (file)
@@ -26,6 +26,7 @@ Version: 3.0.0
 
 - In default deployment CLI (cli) exposes HTTP port 30260 outside of cluster. [`OJSI-129 <https://jira.onap.org/browse/OJSI-129>`_]
 - In default deployment CLI (cli) exposes HTTP port 30271 outside of cluster. [`OJSI-135 <https://jira.onap.org/browse/OJSI-135>`_]
+- CVE-2019-12130 - CLI exposes unprotected APIs/UIs on port 30271. [`OJSI-205 <https://jira.onap.org/browse/OJSI-205>`_]
 
 *Known Vulnerabilities in Used Modules*