Document OJSI-202 (CVE-2019-12127) vulnerability 40/89440/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 21:45:38 +0000 (23:45 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 21:45:38 +0000 (23:45 +0200)
Issue-ID: OJSI-202
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: I46d31d23309f8f34cb1a21d025aac0ff9a5b709a

docs/release-notes.rst

index ae22cb2..3d61e73 100644 (file)
@@ -55,6 +55,7 @@ Summary
 
 * In default deployment OOM (consul-server-ui) exposes HTTP port 30270 outside of cluster. [`OJSI-134 <https://jira.onap.org/browse/OJSI-134>`_]
 * Hard coded password used for all oom deployments [`OJSI-188 <https://jira.onap.org/browse/OJSI-188>`_]
+* CVE-2019-12127 - OOM exposes unprotected API/UI on port 30270 [`OJSI-202 <https://jira.onap.org/browse/OJSI-202>`_]
 
 *Known Vulnerabilities in Used Modules*