Document OJSI-91 vulnerability
[sdnc/oam.git] / docs / release-notes.rst
1 .. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3 Release Notes
4 =============
5
6 Version 1.5.3
7 -------------
8 :Release Date: 2019-06-13
9
10 **New Features**
11
12 The full list of Dublin epics and user stories for SDNC maybe be found at <https://jira.onap.org/issues/?filter=11803>.
13
14 The following list summarizes some of the most significant epics:
15
16 +------------+----------------------------------------------------------------------------+
17 | Jira #     | Abstract                                                                   |
18 +============+============================================================================+
19 | [SDNC-551] | OpenDaylight Fluorine Support                                              |
20 +------------+----------------------------------------------------------------------------+
21 | [SDNC-564] | 5G Use Case                                                                |
22 +------------+----------------------------------------------------------------------------+
23 | [SDNC-565] | CCVPN Use Case Extension                                                   |
24 +------------+----------------------------------------------------------------------------+
25 | [SDNC-570] | SDN-R: Server side component                                               |
26 +------------+----------------------------------------------------------------------------+
27 | [SDNC-579] | SDN-R : UX-Client                                                          |
28 +------------+----------------------------------------------------------------------------+
29 | [SDNC-631] | SDNC support for the PNF Use Case Network Assign for Plug and Play feature |
30 +------------+----------------------------------------------------------------------------+
31
32
33 **Bug Fixes**
34 The full list of bug fixes in the SDNC Dublin release may be found at <https://jira.onap.org/issues/?filter=11805>
35
36 **Known Issues**
37 The full list of known issues in SDNC may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
38
39 **Security Notes**
40
41 *Fixed Security Issues*
42
43 - CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
44   Fixed temporarily by disabling admportal
45 - CVE-2019-12123 `OJSI-42 <https://jira.onap.org/browse/OJSI-42>`_ SDNC service allows for arbitrary code execution in sla/printAsXml form
46   Fixed temporarily by disabling admportal
47 - CVE-2019-12113 `OJSI-43 <https://jira.onap.org/browse/OJSI-43>`_ SDNC service allows for arbitrary code execution in sla/printAsGv form
48   Fixed temporarily by disabling admportal
49 - `OJSI-91 <https://jira.onap.org/browse/OJSI-91>`_ SDNC exposes unprotected API for user creation
50   Fixed temporarily by disabling admportal
51
52 *Known Security Issues*
53
54 *Known Vulnerabilities in Used Modules*
55
56 Quick Links:
57
58 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
59 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
60 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
61
62 Version: 1.4.4
63 --------------
64
65 **Bugs Fixes**
66
67 The following bugs are fixed in the SDNC Casablanca January 2019 maintenance release:
68
69 +------------+------------------------------------------------------------------------------------------+
70 | Jira #     | Abstract                                                                                 |
71 +============+==========================================================================================+
72 | [SDNC-405] | SDNC API documentation is missing on ReadTheDocs                                         |
73 +------------+------------------------------------------------------------------------------------------+
74 | [SDNC-523] | vnf-information.vnf-id validation check should not be mandatory in validate-vnf-input DG |
75 +------------+------------------------------------------------------------------------------------------+
76 | [SDNC-532] | oof query failed due to hostname change, returning unknown host                          |
77 +------------+------------------------------------------------------------------------------------------+
78 | [SDNC-534] | wrong "input" field in DMaaP message template                                            |
79 +------------+------------------------------------------------------------------------------------------+
80 | [SDNC-536] | Upgrade zjsonpatch version to remediate vulnerabilities                                  |
81 +------------+------------------------------------------------------------------------------------------+
82 | [SDNC-537] | Update to spring-boot 2.1.0-RELEASE                                                      |
83 +------------+------------------------------------------------------------------------------------------+
84 | [SDNC-540] | CCVPN closed loop testing failed.                                                        |
85 +------------+------------------------------------------------------------------------------------------+
86 | [SDNC-542] | [PORT] Network Discovery microservice does not log                                       |
87 +------------+------------------------------------------------------------------------------------------+
88 | [SDNC-546] | CCVPN bugs fix for manual free integration test                                          |
89 +------------+------------------------------------------------------------------------------------------+
90 | [SDNC-549] | Retain MD-SAL data on pod recreate                                                       |
91 +------------+------------------------------------------------------------------------------------------+
92
93
94
95 Version: 1.4.3
96 --------------
97
98
99 :Release Date: 2018-11-30
100
101 **New Features**
102
103 The Casablanca release of SDNC introduces the following new features:
104
105         - Network Discovery, in support of POMBA
106         - Support for CCVPN use case
107         - Change Management enhancements
108
109 **Bug Fixes**
110
111 The list of bugs fixed in the SDNC Casablanca release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11544>
112
113
114 **Known Issues**
115
116 The list of known issues in the SDNC project may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
117
118
119 **Security Notes**
120
121 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_.
122
123 Quick Links:
124
125 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
126 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
127 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
128
129 **Upgrade Notes**
130    NA
131
132 **Deprecation Notes**
133    NA
134
135 **Other**
136    NA
137
138 Version: 1.3.4
139 --------------
140
141
142 :Release Date: 2018-07-06
143
144 **New Features**
145
146 The full list of SDNC Beijing Epics and user stories can be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=10791>.  The
147 following table lists the major features included in the Beijing release.
148
149 +------------+-------------------------------------------------------------------------------------------------------------+
150 | Jira #     | Abstract                                                                                                    |
151 +============+=============================================================================================================+
152 | [SDNC-278] | Change management in-place software upgrade execution using Ansible <https://jira.onap.org/browse/SDNC-278> |
153 +------------+-------------------------------------------------------------------------------------------------------------+
154 | [SDNC-163] | Deploy a SDN-C high availability environment - Kubernetes <https://jira.onap.org/browse/SDNC-163>           |
155 +------------+-------------------------------------------------------------------------------------------------------------+
156
157
158 **Bug Fixes**
159
160 The list of bugs fixed in the SDNC Beijing release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11118>
161
162
163 **Known Issues**
164
165 +------------+----------------------------------------------------------------------------------------------------------------------------------+
166 | Jira #     | Abstract                                                                                                                         |
167 +============+==================================================================================================================================+
168 | [SDNC-324] | IPV4_ADDRESS_POOL is empty <https://jira.onap.org/browse/SDNC-324>                                                               |
169 +------------+----------------------------------------------------------------------------------------------------------------------------------+
170 | [SDNC-321] | dgbuilder won't save DG <https://jira.onap.org/browse/SDNC-321>                                                                  |
171 +------------+----------------------------------------------------------------------------------------------------------------------------------+
172 | [SDNC-304] | SDNC OOM intermittent Healthcheck failure - JSONDecodeError - on different startup order <https://jira.onap.org/browse/SDNC-304> |
173 +------------+----------------------------------------------------------------------------------------------------------------------------------+
174 | [SDNC-115] | VNFAPI DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-115>                        |
175 +------------+----------------------------------------------------------------------------------------------------------------------------------+
176 | [SDNC-114] | Generic API DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-114>                   |
177 +------------+----------------------------------------------------------------------------------------------------------------------------------+
178 | [SDNC-106] | VNFAPI DGs contain old openecomp and com.att based plugin references <https://jira.onap.org/browse/SDNC-106>                     |
179 +------------+----------------------------------------------------------------------------------------------------------------------------------+
180 | [SDNC-64]  | SDNC is not setting FromApp identifier in logging MDC <https://jira.onap.org/browse/SDNC-64>                                     |
181 +------------+----------------------------------------------------------------------------------------------------------------------------------+
182
183
184 **Security Notes**
185
186 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_.
187
188 Quick Links:
189
190 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
191 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
192 - `Project Vulnerability Review Table for SDNC <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_
193
194 **Upgrade Notes**
195         NA
196
197 **Deprecation Notes**
198         NA
199
200 **Other**
201         NA
202
203 Version: 1.2.1
204 --------------
205
206 :Release Date: 2018-01-18
207
208 **Bug Fixes**
209
210 - `SDNC-145 <https://jira.onap.org/browse/SDNC-145>`_ Error message refers to wrong parameters
211 - `SDNC-195 <https://jira.onap.org/browse/SDNC-195>`_ UEB listener doesn't insert correct parameters for allotted resources in DB table ALLOTTED_RESOURCE_MODEL
212 - `SDNC-198 <https://jira.onap.org/browse/SDNC-198>`_ CSIT job fails
213 - `SDNC-201 <https://jira.onap.org/browse/SDNC-201>`_ Fix DG bugs from integration tests
214 - `SDNC-202 <https://jira.onap.org/browse/SDNC-202>`_ Search for service -data null match, set vGW LAN IP via Heat
215 - `SDNC-211 <https://jira.onap.org/browse/SDNC-211>`_ Update SDNC Amsterdam branch to use maintenance release versions
216 - `SDNC-212 <https://jira.onap.org/browse/SDNC-212>`_ Duplicate file name
217
218 Version: 1.2.0
219 --------------
220
221 :Release Date: 2017-11-16
222
223 **New Features**
224
225 The ONAP Amsterdam release introduces the following changes to SDNC from
226 the original openECOMP seed code:
227    - Refactored / moved common platform code to new CCSDK project
228    - Refactored code to rename openecomp to onap
229    - Introduced new GENERIC-RESOURCE-API api, used by vCPE and VoLTE use cases
230    - Introduced new docker containers for SDC and DMAAP interfaces
231
232 **Bug Fixes**
233         NA
234 **Known Issues**
235 The following known high priority issues are being worked and are expected to be delivered
236 in release 1.2.1:
237 - `SDNC-179 <https://jira.onap.org/browse/SDNC-179>`_ Failed to make HTTPS connection in restapicall node
238 - `SDNC-181 <https://jira.onap.org/browse/SDNC-181>`_ Change call to brg-wan-ip-address vbrg-wan-ip brg topo activate DG
239 - `SDNC-182 <https://jira.onap.org/browse/SDNC-182>`_ Fix VNI Consistency: Add vG vxlan tunnel setup and bridge domain setup to brg-topo-activate DG
240
241 **Security Issues**
242         NA
243
244 **Upgrade Notes**
245         NA
246
247 **Deprecation Notes**
248         NA
249
250 **Other**
251         NA