Document fixed OJSI tickets 50/96650/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Sat, 5 Oct 2019 21:52:06 +0000 (23:52 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Sat, 5 Oct 2019 21:52:06 +0000 (23:52 +0200)
Issue-ID: OJSI-65
Issue-ID: OJSI-92
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: I5c16b0601ec6a27edd98cc07440f29ac7bed80bd

docs/release-notes.rst

index 8d58756..9f26214 100644 (file)
@@ -28,6 +28,9 @@ Maintanance release with bug fixes and security enhancements.
 
 *Fixed Security Issues*
 
+        * CVE-2019-12122 - ONAP Portal allows to retrieve password of currently active user [`OJSI-65 <https://jira.onap.org/browse/OJSI-65>`_]
+        * CVE-2019-12121 - ONAP Portal is vulnerable for Padding Oracle attack [`OJSI-92 <https://jira.onap.org/browse/OJSI-92>`_]
+
 *Known Security Issues*
 
 *Known Vulnerabilities in Used Modules*