From: Sylvain Desbureaux Date: Thu, 4 Jul 2019 11:15:47 +0000 (+0000) Subject: Merge "Document OJSI-202 (CVE-2019-12127) vulnerability" X-Git-Tag: 5.0.1-ONAP~226 X-Git-Url: https://gerrit.onap.org/r/gitweb?a=commitdiff_plain;h=25f7bae5721a1033707a987fe9d065444a733f7d;hp=7cad1c69abd3c1dbd8665a4d2a5d43a6901ad8c0;p=oom.git Merge "Document OJSI-202 (CVE-2019-12127) vulnerability" --- diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 37d8b3f50a..dc10400dfb 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -55,6 +55,7 @@ Summary * In default deployment OOM (consul-server-ui) exposes HTTP port 30270 outside of cluster. [`OJSI-134 `_] * Hard coded password used for all oom deployments [`OJSI-188 `_] +* CVE-2019-12127 - OOM exposes unprotected API/UI on port 30270 [`OJSI-202 `_] *Known Vulnerabilities in Used Modules*