From: Krzysztof Opasiak Date: Thu, 30 May 2019 13:26:40 +0000 (+0200) Subject: Document OJSI-65 (CVE-2019-1212) vulnerability X-Git-Tag: 3.2.0~307^2~3 X-Git-Url: https://gerrit.onap.org/r/gitweb?p=portal.git;a=commitdiff_plain;h=af68d030bd7f66b680c2b44cd60a19a35aaf9223 Document OJSI-65 (CVE-2019-1212) vulnerability Issue-ID: OJSI-65 Signed-off-by: Krzysztof Opasiak Change-Id: I5c3bee06c2b1da3eca2bb583c57decb35b0f32c0 --- diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 4f954692..fbaf675e 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -37,6 +37,7 @@ We worked on SDK upgrade to integrate with AAF. We partially implemented multi-l *Known Security Issues* * CVE-2019-12317 - Number of XSS vulnerabilities in Portal [`OJSI-15 `_] + * CVE-2019-12122 - ONAP Portal allows to retrieve password of currently active user [`OJSI-65 `_] * In defult deployment PORTAL (portal-app) exposes HTTP port 8989 outside of cluster. [`OJSI-97 `_] * In defult deployment PORTAL (portal-app) exposes HTTP port 30215 outside of cluster. [`OJSI-105 `_] * In defult deployment PORTAL (portal-sdk) exposes HTTP port 30212 outside of cluster. [`OJSI-106 `_]