Document OJSI-199 (CVE-2019-12112) vulnerability
[sdnc/oam.git] / docs / release-notes.rst
1 .. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3 Release Notes
4 =============
5
6 Version 1.5.3
7 -------------
8 :Release Date: 2019-06-13
9
10 **New Features**
11
12 The full list of Dublin epics and user stories for SDNC maybe be found at <https://jira.onap.org/issues/?filter=11803>.
13
14 The following list summarizes some of the most significant epics:
15
16 +------------+----------------------------------------------------------------------------+
17 | Jira #     | Abstract                                                                   |
18 +============+============================================================================+
19 | [SDNC-551] | OpenDaylight Fluorine Support                                              |
20 +------------+----------------------------------------------------------------------------+
21 | [SDNC-564] | 5G Use Case                                                                |
22 +------------+----------------------------------------------------------------------------+
23 | [SDNC-565] | CCVPN Use Case Extension                                                   |
24 +------------+----------------------------------------------------------------------------+
25 | [SDNC-570] | SDN-R: Server side component                                               |
26 +------------+----------------------------------------------------------------------------+
27 | [SDNC-579] | SDN-R : UX-Client                                                          |
28 +------------+----------------------------------------------------------------------------+
29 | [SDNC-631] | SDNC support for the PNF Use Case Network Assign for Plug and Play feature |
30 +------------+----------------------------------------------------------------------------+
31
32
33 **Bug Fixes**
34 The full list of bug fixes in the SDNC Dublin release may be found at <https://jira.onap.org/issues/?filter=11805>
35
36 **Known Issues**
37 The full list of known issues in SDNC may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
38
39 **Security Notes**
40
41 *Fixed Security Issues*
42
43 - CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
44   Fixed temporarily by disabling admportal
45 - CVE-2019-12123 `OJSI-42 <https://jira.onap.org/browse/OJSI-42>`_ SDNC service allows for arbitrary code execution in sla/printAsXml form
46   Fixed temporarily by disabling admportal
47 - CVE-2019-12113 `OJSI-43 <https://jira.onap.org/browse/OJSI-43>`_ SDNC service allows for arbitrary code execution in sla/printAsGv form
48   Fixed temporarily by disabling admportal
49 - `OJSI-91 <https://jira.onap.org/browse/OJSI-91>`_ SDNC exposes unprotected API for user creation
50   Fixed temporarily by disabling admportal
51 - `OJSI-98 <https://jira.onap.org/browse/OJSI-98>`_ In default deployment SDNC (sdnc-portal) exposes HTTP port 30201 outside of cluster.
52   Fixed temporarily by disabling admportal
53 - CVE-2019-12112 `OJSI-199 <https://jira.onap.org/browse/OJSI-199>`_ SDNC service allows for arbitrary code execution in sla/upload form
54   Fixed temporarily by disabling admportal
55
56 *Known Security Issues*
57
58 *Known Vulnerabilities in Used Modules*
59
60 Quick Links:
61
62 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
63 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
64 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
65
66 Version: 1.4.4
67 --------------
68
69 **Bugs Fixes**
70
71 The following bugs are fixed in the SDNC Casablanca January 2019 maintenance release:
72
73 +------------+------------------------------------------------------------------------------------------+
74 | Jira #     | Abstract                                                                                 |
75 +============+==========================================================================================+
76 | [SDNC-405] | SDNC API documentation is missing on ReadTheDocs                                         |
77 +------------+------------------------------------------------------------------------------------------+
78 | [SDNC-523] | vnf-information.vnf-id validation check should not be mandatory in validate-vnf-input DG |
79 +------------+------------------------------------------------------------------------------------------+
80 | [SDNC-532] | oof query failed due to hostname change, returning unknown host                          |
81 +------------+------------------------------------------------------------------------------------------+
82 | [SDNC-534] | wrong "input" field in DMaaP message template                                            |
83 +------------+------------------------------------------------------------------------------------------+
84 | [SDNC-536] | Upgrade zjsonpatch version to remediate vulnerabilities                                  |
85 +------------+------------------------------------------------------------------------------------------+
86 | [SDNC-537] | Update to spring-boot 2.1.0-RELEASE                                                      |
87 +------------+------------------------------------------------------------------------------------------+
88 | [SDNC-540] | CCVPN closed loop testing failed.                                                        |
89 +------------+------------------------------------------------------------------------------------------+
90 | [SDNC-542] | [PORT] Network Discovery microservice does not log                                       |
91 +------------+------------------------------------------------------------------------------------------+
92 | [SDNC-546] | CCVPN bugs fix for manual free integration test                                          |
93 +------------+------------------------------------------------------------------------------------------+
94 | [SDNC-549] | Retain MD-SAL data on pod recreate                                                       |
95 +------------+------------------------------------------------------------------------------------------+
96
97
98
99 Version: 1.4.3
100 --------------
101
102
103 :Release Date: 2018-11-30
104
105 **New Features**
106
107 The Casablanca release of SDNC introduces the following new features:
108
109         - Network Discovery, in support of POMBA
110         - Support for CCVPN use case
111         - Change Management enhancements
112
113 **Bug Fixes**
114
115 The list of bugs fixed in the SDNC Casablanca release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11544>
116
117
118 **Known Issues**
119
120 The list of known issues in the SDNC project may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
121
122
123 **Security Notes**
124
125 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_.
126
127 Quick Links:
128
129 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
130 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
131 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
132
133 **Upgrade Notes**
134    NA
135
136 **Deprecation Notes**
137    NA
138
139 **Other**
140    NA
141
142 Version: 1.3.4
143 --------------
144
145
146 :Release Date: 2018-07-06
147
148 **New Features**
149
150 The full list of SDNC Beijing Epics and user stories can be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=10791>.  The
151 following table lists the major features included in the Beijing release.
152
153 +------------+-------------------------------------------------------------------------------------------------------------+
154 | Jira #     | Abstract                                                                                                    |
155 +============+=============================================================================================================+
156 | [SDNC-278] | Change management in-place software upgrade execution using Ansible <https://jira.onap.org/browse/SDNC-278> |
157 +------------+-------------------------------------------------------------------------------------------------------------+
158 | [SDNC-163] | Deploy a SDN-C high availability environment - Kubernetes <https://jira.onap.org/browse/SDNC-163>           |
159 +------------+-------------------------------------------------------------------------------------------------------------+
160
161
162 **Bug Fixes**
163
164 The list of bugs fixed in the SDNC Beijing release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11118>
165
166
167 **Known Issues**
168
169 +------------+----------------------------------------------------------------------------------------------------------------------------------+
170 | Jira #     | Abstract                                                                                                                         |
171 +============+==================================================================================================================================+
172 | [SDNC-324] | IPV4_ADDRESS_POOL is empty <https://jira.onap.org/browse/SDNC-324>                                                               |
173 +------------+----------------------------------------------------------------------------------------------------------------------------------+
174 | [SDNC-321] | dgbuilder won't save DG <https://jira.onap.org/browse/SDNC-321>                                                                  |
175 +------------+----------------------------------------------------------------------------------------------------------------------------------+
176 | [SDNC-304] | SDNC OOM intermittent Healthcheck failure - JSONDecodeError - on different startup order <https://jira.onap.org/browse/SDNC-304> |
177 +------------+----------------------------------------------------------------------------------------------------------------------------------+
178 | [SDNC-115] | VNFAPI DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-115>                        |
179 +------------+----------------------------------------------------------------------------------------------------------------------------------+
180 | [SDNC-114] | Generic API DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-114>                   |
181 +------------+----------------------------------------------------------------------------------------------------------------------------------+
182 | [SDNC-106] | VNFAPI DGs contain old openecomp and com.att based plugin references <https://jira.onap.org/browse/SDNC-106>                     |
183 +------------+----------------------------------------------------------------------------------------------------------------------------------+
184 | [SDNC-64]  | SDNC is not setting FromApp identifier in logging MDC <https://jira.onap.org/browse/SDNC-64>                                     |
185 +------------+----------------------------------------------------------------------------------------------------------------------------------+
186
187
188 **Security Notes**
189
190 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_.
191
192 Quick Links:
193
194 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
195 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
196 - `Project Vulnerability Review Table for SDNC <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_
197
198 **Upgrade Notes**
199         NA
200
201 **Deprecation Notes**
202         NA
203
204 **Other**
205         NA
206
207 Version: 1.2.1
208 --------------
209
210 :Release Date: 2018-01-18
211
212 **Bug Fixes**
213
214 - `SDNC-145 <https://jira.onap.org/browse/SDNC-145>`_ Error message refers to wrong parameters
215 - `SDNC-195 <https://jira.onap.org/browse/SDNC-195>`_ UEB listener doesn't insert correct parameters for allotted resources in DB table ALLOTTED_RESOURCE_MODEL
216 - `SDNC-198 <https://jira.onap.org/browse/SDNC-198>`_ CSIT job fails
217 - `SDNC-201 <https://jira.onap.org/browse/SDNC-201>`_ Fix DG bugs from integration tests
218 - `SDNC-202 <https://jira.onap.org/browse/SDNC-202>`_ Search for service -data null match, set vGW LAN IP via Heat
219 - `SDNC-211 <https://jira.onap.org/browse/SDNC-211>`_ Update SDNC Amsterdam branch to use maintenance release versions
220 - `SDNC-212 <https://jira.onap.org/browse/SDNC-212>`_ Duplicate file name
221
222 Version: 1.2.0
223 --------------
224
225 :Release Date: 2017-11-16
226
227 **New Features**
228
229 The ONAP Amsterdam release introduces the following changes to SDNC from
230 the original openECOMP seed code:
231    - Refactored / moved common platform code to new CCSDK project
232    - Refactored code to rename openecomp to onap
233    - Introduced new GENERIC-RESOURCE-API api, used by vCPE and VoLTE use cases
234    - Introduced new docker containers for SDC and DMAAP interfaces
235
236 **Bug Fixes**
237         NA
238 **Known Issues**
239 The following known high priority issues are being worked and are expected to be delivered
240 in release 1.2.1:
241 - `SDNC-179 <https://jira.onap.org/browse/SDNC-179>`_ Failed to make HTTPS connection in restapicall node
242 - `SDNC-181 <https://jira.onap.org/browse/SDNC-181>`_ Change call to brg-wan-ip-address vbrg-wan-ip brg topo activate DG
243 - `SDNC-182 <https://jira.onap.org/browse/SDNC-182>`_ Fix VNI Consistency: Add vG vxlan tunnel setup and bridge domain setup to brg-topo-activate DG
244
245 **Security Issues**
246         NA
247
248 **Upgrade Notes**
249         NA
250
251 **Deprecation Notes**
252         NA
253
254 **Other**
255         NA