Document OJSI-77 (CVE-2019-12116) vulnerability 08/89308/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 00:08:05 +0000 (02:08 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 00:08:05 +0000 (02:08 +0200)
Issue-ID: OJSI-77
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: I4a1f92491cc0792659493cecc73575aba4100116

docs/release-notes.rst

index 1cdd7f4..84947c6 100644 (file)
@@ -103,6 +103,7 @@ Security Notes
 
 -  [`OJSI-31 <https://jira.onap.org/browse/OJSI-31>`__\ ] - Unsecured Swagger UI Interface in sdc-wfd-be
 -  CVE-2019-12115 [`OJSI-76 <https://jira.onap.org/browse/OJSI-76>`__\ ] - demo-sdc-sdc-be exposes JDWP on port 4000 which allows for arbitrary code execution
+-  CVE-2019-12116 [`OJSI-77 <https://jira.onap.org/browse/OJSI-77>`__\ ] - demo-sdc-sdc-fe exposes JDWP on port 6000 which allows for arbitrary code execution
 
 *Known Vulnerabilities in Used Modules*