Document OJSI-197 vulnerability
[ccsdk/distribution.git] / docs / release-notes.rst
index 20ddba5..1003c96 100644 (file)
@@ -3,6 +3,56 @@
 Release Notes
 #############
 
+Version 0.4.3
+*************
+:Release Date: 2019-06-13
+
+**New Features**
+
+The full list of Dublin epics and user stories for CCSDK maybe be found at <https://jira.onap.org/issues/?filter=11802>.
+
+The following list summarizes some of the most significant epics:
+
++-------------+------------------------------------------------+
+| Jira #      | Abstract                                       |
++=============+================================================+
+| [CCSDK-575] | Improve E2E Process Automation                 |
++-------------+------------------------------------------------+
+| [CCSDK-840] | S3P - Footprint Optimization                   |
++-------------+------------------------------------------------+
+| [CCSDK-859] | Update to OpenDaylight Fluorine                |
++-------------+------------------------------------------------+
+| [CCSDK-929] | 5G Use Case                                    |
++-------------+------------------------------------------------+
+| [CCSDK-930] | CCVPN Use Case Extension                       |
++-------------+------------------------------------------------+
+
+
+**Bug Fixes**
+The full list of bug fixes in the CCSDK Dublin release may be found at <https://jira.onap.org/issues/?filter=11804>
+
+**Known Issues**
+The full list of known issues in CCSDK may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11341>
+
+**Security Notes**
+
+*Fixed Security Issues*
+
+*Known Security Issues*
+
+        * In default deployment CCSDK (netbox-nginx) exposes HTTP port 30420 outside of cluster. [`OJSI-160 <https://jira.onap.org/browse/OJSI-160>`_]
+        * In default deployment CCSDK (cds-ui) exposes HTTP port 30497 outside of cluster. [`OJSI-196 <https://jira.onap.org/browse/OJSI-196>`_]
+        * In default deployment CCSDK (cds-blueprints-processor-http) exposes HTTP port 30499 outside of cluster. [`OJSI-197 <https://jira.onap.org/browse/OJSI-197>`_]
+
+*Known Vulnerabilities in Used Modules*
+
+Quick Links:
+       - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
+
+       - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
+
+       - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=51282469>`_
+
 Version: 0.3.3
 **************
 
@@ -11,30 +61,32 @@ Version: 0.3.3
 ** Bug Fixes **
 The following bugs are fixed in the CCSDK Casablanca January 2019 maintenance release:
 
-+-------------+--------------------------------------------------------------------+
-| Jira #      | Abstract                                                           |
-+=============+====================================================================+
-| [CCSDK-727] | Do not prepend "sub" for subnet net id                             |
-+-------------+--------------------------------------------------------------------+
-| [CCSDK-728] | Self serve DG adjustement for unassign                             |
-+-------------+--------------------------------------------------------------------+
-| [CCSDK-740] | Restore inventory-response-item definition to the original version |
-+-------------+--------------------------------------------------------------------+
-| [CCSDK-765] | Upgrade jackson version to 2.8.9                                   |
-+-------------+--------------------------------------------------------------------+
-| [CCSDK-777] | Release version contains some snapshots                            |
-+-------------+--------------------------------------------------------------------+
-| [CCSDK-843] | Compile error due to old snapshot dependency                       |
-+-------------+--------------------------------------------------------------------+
++-------------+-------------------------------------------------------------------------------+
+| Jira #      | Abstract                                                                      |
++=============+===============================================================================+
+| [CCSDK-727] | Do not prepend "sub" for subnet net id                                        |
++-------------+-------------------------------------------------------------------------------+
+| [CCSDK-728] | Self serve DG adjustement for unassign                                        |
++-------------+-------------------------------------------------------------------------------+
+| [CCSDK-740] | Restore inventory-response-item definition to the original version            |
++-------------+-------------------------------------------------------------------------------+
+| [CCSDK-765] | Upgrade jackson version to 2.8.9                                              |
++-------------+-------------------------------------------------------------------------------+
+| [CCSDK-777] | Release version contains some snapshots                                       |
++-------------+-------------------------------------------------------------------------------+
+| [CCSDK-843] | Compile error due to old snapshot dependency                                  |
++-------------+-------------------------------------------------------------------------------+
+| [CCSDK-935] | restapicall JsonParser failed if response contains : as part of response body |
++-------------+-------------------------------------------------------------------------------+
 
 **Known Issues**
 The full list of known issues in CCSDK may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11341>
 
 Quick Links:
    - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
-   
+
    - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
-   
+
    - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=45300857>`_
 
 Version: 0.3.2
@@ -68,9 +120,9 @@ The full list of known issues in CCSDK may be found in the ONAP Jira at <https:/
 
 Quick Links:
        - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
-       
+
        - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
-       
+
        - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=45300857>`_
 
 Version: 0.2.4
@@ -124,9 +176,9 @@ CCSDK code has been formally scanned during build time using NexusIQ and all Cri
 
 Quick Links:
        - `CCSDK project page <https://wiki.onap.org/display/DW/Common+Controller+SDK+Project>`_
-       
+
        - `Passing Badge information for CCSDK <https://bestpractices.coreinfrastructure.org/en/projects/1630>`_
-       
+
        - `Project Vulnerability Review Table for CCSDK <https://wiki.onap.org/pages/viewpage.action?pageId=28379011>`_
 
 **Upgrade Notes**
@@ -180,4 +232,3 @@ The Common Controller SDK provides the following functionality :
 **Deprecation Notes**
 
 **Other**
-