Document OJSI-99 vulnerability
[sdnc/oam.git] / docs / release-notes.rst
1 .. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3 Release Notes
4 =============
5
6 Version 1.5.3
7 -------------
8 :Release Date: 2019-06-13
9
10 **New Features**
11
12 The full list of Dublin epics and user stories for SDNC maybe be found at <https://jira.onap.org/issues/?filter=11803>.
13
14 The following list summarizes some of the most significant epics:
15
16 +------------+----------------------------------------------------------------------------+
17 | Jira #     | Abstract                                                                   |
18 +============+============================================================================+
19 | [SDNC-551] | OpenDaylight Fluorine Support                                              |
20 +------------+----------------------------------------------------------------------------+
21 | [SDNC-564] | 5G Use Case                                                                |
22 +------------+----------------------------------------------------------------------------+
23 | [SDNC-565] | CCVPN Use Case Extension                                                   |
24 +------------+----------------------------------------------------------------------------+
25 | [SDNC-570] | SDN-R: Server side component                                               |
26 +------------+----------------------------------------------------------------------------+
27 | [SDNC-579] | SDN-R : UX-Client                                                          |
28 +------------+----------------------------------------------------------------------------+
29 | [SDNC-631] | SDNC support for the PNF Use Case Network Assign for Plug and Play feature |
30 +------------+----------------------------------------------------------------------------+
31
32
33 **Bug Fixes**
34 The full list of bug fixes in the SDNC Dublin release may be found at <https://jira.onap.org/issues/?filter=11805>
35
36 **Known Issues**
37 The full list of known issues in SDNC may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
38
39 **Security Notes**
40
41 *Fixed Security Issues*
42
43 - CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
44   Fixed temporarily by disabling admportal
45 - CVE-2019-12123 `OJSI-42 <https://jira.onap.org/browse/OJSI-42>`_ SDNC service allows for arbitrary code execution in sla/printAsXml form
46   Fixed temporarily by disabling admportal
47 - CVE-2019-12113 `OJSI-43 <https://jira.onap.org/browse/OJSI-43>`_ SDNC service allows for arbitrary code execution in sla/printAsGv form
48   Fixed temporarily by disabling admportal
49 - `OJSI-91 <https://jira.onap.org/browse/OJSI-91>`_ SDNC exposes unprotected API for user creation
50   Fixed temporarily by disabling admportal
51 - `OJSI-98 <https://jira.onap.org/browse/OJSI-98>`_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster.
52   Fixed temporarily by disabling admportal
53 - CVE-2019-12112 `OJSI-199 <https://jira.onap.org/browse/OJSI-199>`_ SDNC service allows for arbitrary code execution in sla/upload form
54   Fixed temporarily by disabling admportal
55
56 *Known Security Issues*
57
58 - `OJSI-34 <https://jira.onap.org/browse/OJSI-34>`_ Multiple SQL Injection issues in SDNC
59 - `OJSI-99 <https://jira.onap.org/browse/OJSI-99>`_ In default deployment SDNC (sdnc) exposes HTTP port 30202 outside of cluster.
60
61 *Known Vulnerabilities in Used Modules*
62
63 Quick Links:
64
65 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
66 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
67 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
68
69 Version: 1.4.4
70 --------------
71
72 **Bugs Fixes**
73
74 The following bugs are fixed in the SDNC Casablanca January 2019 maintenance release:
75
76 +------------+------------------------------------------------------------------------------------------+
77 | Jira #     | Abstract                                                                                 |
78 +============+==========================================================================================+
79 | [SDNC-405] | SDNC API documentation is missing on ReadTheDocs                                         |
80 +------------+------------------------------------------------------------------------------------------+
81 | [SDNC-523] | vnf-information.vnf-id validation check should not be mandatory in validate-vnf-input DG |
82 +------------+------------------------------------------------------------------------------------------+
83 | [SDNC-532] | oof query failed due to hostname change, returning unknown host                          |
84 +------------+------------------------------------------------------------------------------------------+
85 | [SDNC-534] | wrong "input" field in DMaaP message template                                            |
86 +------------+------------------------------------------------------------------------------------------+
87 | [SDNC-536] | Upgrade zjsonpatch version to remediate vulnerabilities                                  |
88 +------------+------------------------------------------------------------------------------------------+
89 | [SDNC-537] | Update to spring-boot 2.1.0-RELEASE                                                      |
90 +------------+------------------------------------------------------------------------------------------+
91 | [SDNC-540] | CCVPN closed loop testing failed.                                                        |
92 +------------+------------------------------------------------------------------------------------------+
93 | [SDNC-542] | [PORT] Network Discovery microservice does not log                                       |
94 +------------+------------------------------------------------------------------------------------------+
95 | [SDNC-546] | CCVPN bugs fix for manual free integration test                                          |
96 +------------+------------------------------------------------------------------------------------------+
97 | [SDNC-549] | Retain MD-SAL data on pod recreate                                                       |
98 +------------+------------------------------------------------------------------------------------------+
99
100
101
102 Version: 1.4.3
103 --------------
104
105
106 :Release Date: 2018-11-30
107
108 **New Features**
109
110 The Casablanca release of SDNC introduces the following new features:
111
112         - Network Discovery, in support of POMBA
113         - Support for CCVPN use case
114         - Change Management enhancements
115
116 **Bug Fixes**
117
118 The list of bugs fixed in the SDNC Casablanca release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11544>
119
120
121 **Known Issues**
122
123 The list of known issues in the SDNC project may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
124
125
126 **Security Notes**
127
128 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_.
129
130 Quick Links:
131
132 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
133 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
134 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
135
136 **Upgrade Notes**
137    NA
138
139 **Deprecation Notes**
140    NA
141
142 **Other**
143    NA
144
145 Version: 1.3.4
146 --------------
147
148
149 :Release Date: 2018-07-06
150
151 **New Features**
152
153 The full list of SDNC Beijing Epics and user stories can be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=10791>.  The
154 following table lists the major features included in the Beijing release.
155
156 +------------+-------------------------------------------------------------------------------------------------------------+
157 | Jira #     | Abstract                                                                                                    |
158 +============+=============================================================================================================+
159 | [SDNC-278] | Change management in-place software upgrade execution using Ansible <https://jira.onap.org/browse/SDNC-278> |
160 +------------+-------------------------------------------------------------------------------------------------------------+
161 | [SDNC-163] | Deploy a SDN-C high availability environment - Kubernetes <https://jira.onap.org/browse/SDNC-163>           |
162 +------------+-------------------------------------------------------------------------------------------------------------+
163
164
165 **Bug Fixes**
166
167 The list of bugs fixed in the SDNC Beijing release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11118>
168
169
170 **Known Issues**
171
172 +------------+----------------------------------------------------------------------------------------------------------------------------------+
173 | Jira #     | Abstract                                                                                                                         |
174 +============+==================================================================================================================================+
175 | [SDNC-324] | IPV4_ADDRESS_POOL is empty <https://jira.onap.org/browse/SDNC-324>                                                               |
176 +------------+----------------------------------------------------------------------------------------------------------------------------------+
177 | [SDNC-321] | dgbuilder won't save DG <https://jira.onap.org/browse/SDNC-321>                                                                  |
178 +------------+----------------------------------------------------------------------------------------------------------------------------------+
179 | [SDNC-304] | SDNC OOM intermittent Healthcheck failure - JSONDecodeError - on different startup order <https://jira.onap.org/browse/SDNC-304> |
180 +------------+----------------------------------------------------------------------------------------------------------------------------------+
181 | [SDNC-115] | VNFAPI DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-115>                        |
182 +------------+----------------------------------------------------------------------------------------------------------------------------------+
183 | [SDNC-114] | Generic API DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-114>                   |
184 +------------+----------------------------------------------------------------------------------------------------------------------------------+
185 | [SDNC-106] | VNFAPI DGs contain old openecomp and com.att based plugin references <https://jira.onap.org/browse/SDNC-106>                     |
186 +------------+----------------------------------------------------------------------------------------------------------------------------------+
187 | [SDNC-64]  | SDNC is not setting FromApp identifier in logging MDC <https://jira.onap.org/browse/SDNC-64>                                     |
188 +------------+----------------------------------------------------------------------------------------------------------------------------------+
189
190
191 **Security Notes**
192
193 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_.
194
195 Quick Links:
196
197 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
198 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
199 - `Project Vulnerability Review Table for SDNC <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_
200
201 **Upgrade Notes**
202         NA
203
204 **Deprecation Notes**
205         NA
206
207 **Other**
208         NA
209
210 Version: 1.2.1
211 --------------
212
213 :Release Date: 2018-01-18
214
215 **Bug Fixes**
216
217 - `SDNC-145 <https://jira.onap.org/browse/SDNC-145>`_ Error message refers to wrong parameters
218 - `SDNC-195 <https://jira.onap.org/browse/SDNC-195>`_ UEB listener doesn't insert correct parameters for allotted resources in DB table ALLOTTED_RESOURCE_MODEL
219 - `SDNC-198 <https://jira.onap.org/browse/SDNC-198>`_ CSIT job fails
220 - `SDNC-201 <https://jira.onap.org/browse/SDNC-201>`_ Fix DG bugs from integration tests
221 - `SDNC-202 <https://jira.onap.org/browse/SDNC-202>`_ Search for service -data null match, set vGW LAN IP via Heat
222 - `SDNC-211 <https://jira.onap.org/browse/SDNC-211>`_ Update SDNC Amsterdam branch to use maintenance release versions
223 - `SDNC-212 <https://jira.onap.org/browse/SDNC-212>`_ Duplicate file name
224
225 Version: 1.2.0
226 --------------
227
228 :Release Date: 2017-11-16
229
230 **New Features**
231
232 The ONAP Amsterdam release introduces the following changes to SDNC from
233 the original openECOMP seed code:
234    - Refactored / moved common platform code to new CCSDK project
235    - Refactored code to rename openecomp to onap
236    - Introduced new GENERIC-RESOURCE-API api, used by vCPE and VoLTE use cases
237    - Introduced new docker containers for SDC and DMAAP interfaces
238
239 **Bug Fixes**
240         NA
241 **Known Issues**
242 The following known high priority issues are being worked and are expected to be delivered
243 in release 1.2.1:
244 - `SDNC-179 <https://jira.onap.org/browse/SDNC-179>`_ Failed to make HTTPS connection in restapicall node
245 - `SDNC-181 <https://jira.onap.org/browse/SDNC-181>`_ Change call to brg-wan-ip-address vbrg-wan-ip brg topo activate DG
246 - `SDNC-182 <https://jira.onap.org/browse/SDNC-182>`_ Fix VNI Consistency: Add vG vxlan tunnel setup and bridge domain setup to brg-topo-activate DG
247
248 **Security Issues**
249         NA
250
251 **Upgrade Notes**
252         NA
253
254 **Deprecation Notes**
255         NA
256
257 **Other**
258         NA