Document OJSI-34 vulnerability
[sdnc/oam.git] / docs / release-notes.rst
1 .. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3 Release Notes
4 =============
5
6 Version 1.5.3
7 -------------
8 :Release Date: 2019-06-13
9
10 **New Features**
11
12 The full list of Dublin epics and user stories for SDNC maybe be found at <https://jira.onap.org/issues/?filter=11803>.
13
14 The following list summarizes some of the most significant epics:
15
16 +------------+----------------------------------------------------------------------------+
17 | Jira #     | Abstract                                                                   |
18 +============+============================================================================+
19 | [SDNC-551] | OpenDaylight Fluorine Support                                              |
20 +------------+----------------------------------------------------------------------------+
21 | [SDNC-564] | 5G Use Case                                                                |
22 +------------+----------------------------------------------------------------------------+
23 | [SDNC-565] | CCVPN Use Case Extension                                                   |
24 +------------+----------------------------------------------------------------------------+
25 | [SDNC-570] | SDN-R: Server side component                                               |
26 +------------+----------------------------------------------------------------------------+
27 | [SDNC-579] | SDN-R : UX-Client                                                          |
28 +------------+----------------------------------------------------------------------------+
29 | [SDNC-631] | SDNC support for the PNF Use Case Network Assign for Plug and Play feature |
30 +------------+----------------------------------------------------------------------------+
31
32
33 **Bug Fixes**
34 The full list of bug fixes in the SDNC Dublin release may be found at <https://jira.onap.org/issues/?filter=11805>
35
36 **Known Issues**
37 The full list of known issues in SDNC may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
38
39 **Security Notes**
40
41 *Fixed Security Issues*
42
43 - CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
44   Fixed temporarily by disabling admportal
45 - CVE-2019-12123 `OJSI-42 <https://jira.onap.org/browse/OJSI-42>`_ SDNC service allows for arbitrary code execution in sla/printAsXml form
46   Fixed temporarily by disabling admportal
47 - CVE-2019-12113 `OJSI-43 <https://jira.onap.org/browse/OJSI-43>`_ SDNC service allows for arbitrary code execution in sla/printAsGv form
48   Fixed temporarily by disabling admportal
49 - `OJSI-91 <https://jira.onap.org/browse/OJSI-91>`_ SDNC exposes unprotected API for user creation
50   Fixed temporarily by disabling admportal
51 - `OJSI-98 <https://jira.onap.org/browse/OJSI-98>`_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster.
52   Fixed temporarily by disabling admportal
53 - CVE-2019-12112 `OJSI-199 <https://jira.onap.org/browse/OJSI-199>`_ SDNC service allows for arbitrary code execution in sla/upload form
54   Fixed temporarily by disabling admportal
55
56 *Known Security Issues*
57
58 - `OJSI-34 <https://jira.onap.org/browse/OJSI-34>`_ Multiple SQL Injection issues in SDNC
59
60 *Known Vulnerabilities in Used Modules*
61
62 Quick Links:
63
64 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
65 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
66 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
67
68 Version: 1.4.4
69 --------------
70
71 **Bugs Fixes**
72
73 The following bugs are fixed in the SDNC Casablanca January 2019 maintenance release:
74
75 +------------+------------------------------------------------------------------------------------------+
76 | Jira #     | Abstract                                                                                 |
77 +============+==========================================================================================+
78 | [SDNC-405] | SDNC API documentation is missing on ReadTheDocs                                         |
79 +------------+------------------------------------------------------------------------------------------+
80 | [SDNC-523] | vnf-information.vnf-id validation check should not be mandatory in validate-vnf-input DG |
81 +------------+------------------------------------------------------------------------------------------+
82 | [SDNC-532] | oof query failed due to hostname change, returning unknown host                          |
83 +------------+------------------------------------------------------------------------------------------+
84 | [SDNC-534] | wrong "input" field in DMaaP message template                                            |
85 +------------+------------------------------------------------------------------------------------------+
86 | [SDNC-536] | Upgrade zjsonpatch version to remediate vulnerabilities                                  |
87 +------------+------------------------------------------------------------------------------------------+
88 | [SDNC-537] | Update to spring-boot 2.1.0-RELEASE                                                      |
89 +------------+------------------------------------------------------------------------------------------+
90 | [SDNC-540] | CCVPN closed loop testing failed.                                                        |
91 +------------+------------------------------------------------------------------------------------------+
92 | [SDNC-542] | [PORT] Network Discovery microservice does not log                                       |
93 +------------+------------------------------------------------------------------------------------------+
94 | [SDNC-546] | CCVPN bugs fix for manual free integration test                                          |
95 +------------+------------------------------------------------------------------------------------------+
96 | [SDNC-549] | Retain MD-SAL data on pod recreate                                                       |
97 +------------+------------------------------------------------------------------------------------------+
98
99
100
101 Version: 1.4.3
102 --------------
103
104
105 :Release Date: 2018-11-30
106
107 **New Features**
108
109 The Casablanca release of SDNC introduces the following new features:
110
111         - Network Discovery, in support of POMBA
112         - Support for CCVPN use case
113         - Change Management enhancements
114
115 **Bug Fixes**
116
117 The list of bugs fixed in the SDNC Casablanca release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11544>
118
119
120 **Known Issues**
121
122 The list of known issues in the SDNC project may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
123
124
125 **Security Notes**
126
127 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_.
128
129 Quick Links:
130
131 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
132 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
133 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
134
135 **Upgrade Notes**
136    NA
137
138 **Deprecation Notes**
139    NA
140
141 **Other**
142    NA
143
144 Version: 1.3.4
145 --------------
146
147
148 :Release Date: 2018-07-06
149
150 **New Features**
151
152 The full list of SDNC Beijing Epics and user stories can be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=10791>.  The
153 following table lists the major features included in the Beijing release.
154
155 +------------+-------------------------------------------------------------------------------------------------------------+
156 | Jira #     | Abstract                                                                                                    |
157 +============+=============================================================================================================+
158 | [SDNC-278] | Change management in-place software upgrade execution using Ansible <https://jira.onap.org/browse/SDNC-278> |
159 +------------+-------------------------------------------------------------------------------------------------------------+
160 | [SDNC-163] | Deploy a SDN-C high availability environment - Kubernetes <https://jira.onap.org/browse/SDNC-163>           |
161 +------------+-------------------------------------------------------------------------------------------------------------+
162
163
164 **Bug Fixes**
165
166 The list of bugs fixed in the SDNC Beijing release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11118>
167
168
169 **Known Issues**
170
171 +------------+----------------------------------------------------------------------------------------------------------------------------------+
172 | Jira #     | Abstract                                                                                                                         |
173 +============+==================================================================================================================================+
174 | [SDNC-324] | IPV4_ADDRESS_POOL is empty <https://jira.onap.org/browse/SDNC-324>                                                               |
175 +------------+----------------------------------------------------------------------------------------------------------------------------------+
176 | [SDNC-321] | dgbuilder won't save DG <https://jira.onap.org/browse/SDNC-321>                                                                  |
177 +------------+----------------------------------------------------------------------------------------------------------------------------------+
178 | [SDNC-304] | SDNC OOM intermittent Healthcheck failure - JSONDecodeError - on different startup order <https://jira.onap.org/browse/SDNC-304> |
179 +------------+----------------------------------------------------------------------------------------------------------------------------------+
180 | [SDNC-115] | VNFAPI DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-115>                        |
181 +------------+----------------------------------------------------------------------------------------------------------------------------------+
182 | [SDNC-114] | Generic API DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-114>                   |
183 +------------+----------------------------------------------------------------------------------------------------------------------------------+
184 | [SDNC-106] | VNFAPI DGs contain old openecomp and com.att based plugin references <https://jira.onap.org/browse/SDNC-106>                     |
185 +------------+----------------------------------------------------------------------------------------------------------------------------------+
186 | [SDNC-64]  | SDNC is not setting FromApp identifier in logging MDC <https://jira.onap.org/browse/SDNC-64>                                     |
187 +------------+----------------------------------------------------------------------------------------------------------------------------------+
188
189
190 **Security Notes**
191
192 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_.
193
194 Quick Links:
195
196 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
197 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
198 - `Project Vulnerability Review Table for SDNC <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_
199
200 **Upgrade Notes**
201         NA
202
203 **Deprecation Notes**
204         NA
205
206 **Other**
207         NA
208
209 Version: 1.2.1
210 --------------
211
212 :Release Date: 2018-01-18
213
214 **Bug Fixes**
215
216 - `SDNC-145 <https://jira.onap.org/browse/SDNC-145>`_ Error message refers to wrong parameters
217 - `SDNC-195 <https://jira.onap.org/browse/SDNC-195>`_ UEB listener doesn't insert correct parameters for allotted resources in DB table ALLOTTED_RESOURCE_MODEL
218 - `SDNC-198 <https://jira.onap.org/browse/SDNC-198>`_ CSIT job fails
219 - `SDNC-201 <https://jira.onap.org/browse/SDNC-201>`_ Fix DG bugs from integration tests
220 - `SDNC-202 <https://jira.onap.org/browse/SDNC-202>`_ Search for service -data null match, set vGW LAN IP via Heat
221 - `SDNC-211 <https://jira.onap.org/browse/SDNC-211>`_ Update SDNC Amsterdam branch to use maintenance release versions
222 - `SDNC-212 <https://jira.onap.org/browse/SDNC-212>`_ Duplicate file name
223
224 Version: 1.2.0
225 --------------
226
227 :Release Date: 2017-11-16
228
229 **New Features**
230
231 The ONAP Amsterdam release introduces the following changes to SDNC from
232 the original openECOMP seed code:
233    - Refactored / moved common platform code to new CCSDK project
234    - Refactored code to rename openecomp to onap
235    - Introduced new GENERIC-RESOURCE-API api, used by vCPE and VoLTE use cases
236    - Introduced new docker containers for SDC and DMAAP interfaces
237
238 **Bug Fixes**
239         NA
240 **Known Issues**
241 The following known high priority issues are being worked and are expected to be delivered
242 in release 1.2.1:
243 - `SDNC-179 <https://jira.onap.org/browse/SDNC-179>`_ Failed to make HTTPS connection in restapicall node
244 - `SDNC-181 <https://jira.onap.org/browse/SDNC-181>`_ Change call to brg-wan-ip-address vbrg-wan-ip brg topo activate DG
245 - `SDNC-182 <https://jira.onap.org/browse/SDNC-182>`_ Fix VNI Consistency: Add vG vxlan tunnel setup and bridge domain setup to brg-topo-activate DG
246
247 **Security Issues**
248         NA
249
250 **Upgrade Notes**
251         NA
252
253 **Deprecation Notes**
254         NA
255
256 **Other**
257         NA