From: Krzysztof Opasiak Date: Wed, 5 Jun 2019 21:32:21 +0000 (+0200) Subject: Document OJSI-112 vulnerability X-Git-Tag: 1.6.0~37 X-Git-Url: https://gerrit.onap.org/r/gitweb?a=commitdiff_plain;h=refs%2Fchanges%2F34%2F89434%2F1;p=appc.git Document OJSI-112 vulnerability Issue-ID: OJSI-112 Signed-off-by: Krzysztof Opasiak Change-Id: Id28f332ddcdd5c69f5a82758d05c10d19606faff --- diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 4123ff95c..5ca3186c0 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -119,6 +119,7 @@ The Dublin release added the following functionality: - `OJSI-29 `_ - Unsecured Swagger UI Interface in AAPC - CVE-2019-12124 `OJSI-63 `_ - APPC exposes Jolokia Interface which allows to read and overwrite any arbitrary file - `OJSI-95 `_ - appc-cdt allows to impersonate any user by setting USER_ID + - `OJSI-112 `_ - In default deployment APPC (appc-dgbuilder) exposes HTTP port 30228 outside of cluster. *Known Vulnerabilities in Used Modules*