Document OJSI-102 vulnerability 15/89315/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 00:13:05 +0000 (02:13 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 00:13:05 +0000 (02:13 +0200)
Issue-ID: OJSI-102
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: Ibfa34510c9522f3d6600a8f65a7239b12ef57f92

docs/release-notes.rst

index 6dfb77a..3af8f5a 100644 (file)
@@ -110,6 +110,7 @@ Security Notes
 -  [`OJSI-90 <https://jira.onap.org/browse/OJSI-90>`__\ ] - SDC exposes unprotected API for user creation
 -  [`OJSI-94 <https://jira.onap.org/browse/OJSI-94>`__\ ] - sdc-wfd-fe allows to impersonate any user by setting USER_ID
 -  [`OJSI-101 <https://jira.onap.org/browse/OJSI-101>`__\ ] - In default deployment SDC (sdc-be) exposes HTTP port 30205 outside of cluster.
+-  [`OJSI-102 <https://jira.onap.org/browse/OJSI-102>`__\ ] - In default deployment SDC (sdc-fe) exposes HTTP port 30206 outside of cluster.
 
 *Known Vulnerabilities in Used Modules*