Document OJSI-63 (CVE-2019-12124) vulnerability 32/89432/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 21:30:42 +0000 (23:30 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 21:30:42 +0000 (23:30 +0200)
Issue-ID: OJSI-63
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: Ide989877e0f2765302ad423c0b421e972b4e8046

docs/release-notes.rst

index a6aad66..fa09a4e 100644 (file)
@@ -117,6 +117,7 @@ The Dublin release added the following functionality:
 
       - CVE-2019-12316 `OJSI-25 <https://jira.onap.org/browse/OJSI-25>`_ - SQL Injection in APPC
       - `OJSI-29 <https://jira.onap.org/browse/OJSI-29>`_ - Unsecured Swagger UI Interface in AAPC
+      - CVE-2019-12124 `OJSI-63 <https://jira.onap.org/browse/OJSI-63>`_ - APPC exposes Jolokia Interface which allows to read and overwrite any arbitrary file
 
 *Known Vulnerabilities in Used Modules*