From: Dan Timoney Date: Fri, 7 Jun 2019 02:12:14 +0000 (+0000) Subject: Merge "Document OJSI-199 (CVE-2019-12112) vulnerability" X-Git-Url: https://gerrit.onap.org/r/gitweb?a=commitdiff_plain;h=fd4db3019ed2aa13766de17de8ebf52226b839c2;hp=a25e29ba185d4e4e337ea1cf9c8103b64dfdc737;p=sdnc%2Foam.git Merge "Document OJSI-199 (CVE-2019-12112) vulnerability" --- diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 67034c6b..56443f1b 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -50,6 +50,8 @@ The full list of known issues in SDNC may be found in the ONAP Jira at `_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster. Fixed temporarily by disabling admportal +- CVE-2019-12112 `OJSI-199 `_ SDNC service allows for arbitrary code execution in sla/upload form + Fixed temporarily by disabling admportal *Known Security Issues*