Document OJSI-43 (CVE-2019-12113) vulnerability
[sdnc/oam.git] / docs / release-notes.rst
1 .. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3 Release Notes
4 =============
5
6 Version 1.5.3
7 -------------
8 :Release Date: 2019-06-13
9
10 **New Features**
11
12 The full list of Dublin epics and user stories for SDNC maybe be found at <https://jira.onap.org/issues/?filter=11803>.
13
14 The following list summarizes some of the most significant epics:
15
16 +------------+----------------------------------------------------------------------------+
17 | Jira #     | Abstract                                                                   |
18 +============+============================================================================+
19 | [SDNC-551] | OpenDaylight Fluorine Support                                              |
20 +------------+----------------------------------------------------------------------------+
21 | [SDNC-564] | 5G Use Case                                                                |
22 +------------+----------------------------------------------------------------------------+
23 | [SDNC-565] | CCVPN Use Case Extension                                                   |
24 +------------+----------------------------------------------------------------------------+
25 | [SDNC-570] | SDN-R: Server side component                                               |
26 +------------+----------------------------------------------------------------------------+
27 | [SDNC-579] | SDN-R : UX-Client                                                          |
28 +------------+----------------------------------------------------------------------------+
29 | [SDNC-631] | SDNC support for the PNF Use Case Network Assign for Plug and Play feature |
30 +------------+----------------------------------------------------------------------------+
31
32
33 **Bug Fixes**
34 The full list of bug fixes in the SDNC Dublin release may be found at <https://jira.onap.org/issues/?filter=11805>
35
36 **Known Issues**
37 The full list of known issues in SDNC may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
38
39 **Security Notes**
40
41 *Fixed Security Issues*
42
43 - CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
44   Fixed temporarily by disabling admportal
45 - CVE-2019-12123 `OJSI-42 <https://jira.onap.org/browse/OJSI-42>`_ SDNC service allows for arbitrary code execution in sla/printAsXml form
46   Fixed temporarily by disabling admportal
47 - CVE-2019-12113 `OJSI-43 <https://jira.onap.org/browse/OJSI-43>`_ SDNC service allows for arbitrary code execution in sla/printAsGv form
48   Fixed temporarily by disabling admportal
49
50 *Known Security Issues*
51
52 *Known Vulnerabilities in Used Modules*
53
54 Quick Links:
55
56 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
57 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
58 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
59
60 Version: 1.4.4
61 --------------
62
63 **Bugs Fixes**
64
65 The following bugs are fixed in the SDNC Casablanca January 2019 maintenance release:
66
67 +------------+------------------------------------------------------------------------------------------+
68 | Jira #     | Abstract                                                                                 |
69 +============+==========================================================================================+
70 | [SDNC-405] | SDNC API documentation is missing on ReadTheDocs                                         |
71 +------------+------------------------------------------------------------------------------------------+
72 | [SDNC-523] | vnf-information.vnf-id validation check should not be mandatory in validate-vnf-input DG |
73 +------------+------------------------------------------------------------------------------------------+
74 | [SDNC-532] | oof query failed due to hostname change, returning unknown host                          |
75 +------------+------------------------------------------------------------------------------------------+
76 | [SDNC-534] | wrong "input" field in DMaaP message template                                            |
77 +------------+------------------------------------------------------------------------------------------+
78 | [SDNC-536] | Upgrade zjsonpatch version to remediate vulnerabilities                                  |
79 +------------+------------------------------------------------------------------------------------------+
80 | [SDNC-537] | Update to spring-boot 2.1.0-RELEASE                                                      |
81 +------------+------------------------------------------------------------------------------------------+
82 | [SDNC-540] | CCVPN closed loop testing failed.                                                        |
83 +------------+------------------------------------------------------------------------------------------+
84 | [SDNC-542] | [PORT] Network Discovery microservice does not log                                       |
85 +------------+------------------------------------------------------------------------------------------+
86 | [SDNC-546] | CCVPN bugs fix for manual free integration test                                          |
87 +------------+------------------------------------------------------------------------------------------+
88 | [SDNC-549] | Retain MD-SAL data on pod recreate                                                       |
89 +------------+------------------------------------------------------------------------------------------+
90
91
92
93 Version: 1.4.3
94 --------------
95
96
97 :Release Date: 2018-11-30
98
99 **New Features**
100
101 The Casablanca release of SDNC introduces the following new features:
102
103         - Network Discovery, in support of POMBA
104         - Support for CCVPN use case
105         - Change Management enhancements
106
107 **Bug Fixes**
108
109 The list of bugs fixed in the SDNC Casablanca release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11544>
110
111
112 **Known Issues**
113
114 The list of known issues in the SDNC project may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11119>
115
116
117 **Security Notes**
118
119 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_.
120
121 Quick Links:
122
123 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
124 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
125 - `Project Vulnerability Review Table for Casablanca Release <https://wiki.onap.org/pages/viewpage.action?pageId=45307811>`_
126
127 **Upgrade Notes**
128    NA
129
130 **Deprecation Notes**
131    NA
132
133 **Other**
134    NA
135
136 Version: 1.3.4
137 --------------
138
139
140 :Release Date: 2018-07-06
141
142 **New Features**
143
144 The full list of SDNC Beijing Epics and user stories can be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=10791>.  The
145 following table lists the major features included in the Beijing release.
146
147 +------------+-------------------------------------------------------------------------------------------------------------+
148 | Jira #     | Abstract                                                                                                    |
149 +============+=============================================================================================================+
150 | [SDNC-278] | Change management in-place software upgrade execution using Ansible <https://jira.onap.org/browse/SDNC-278> |
151 +------------+-------------------------------------------------------------------------------------------------------------+
152 | [SDNC-163] | Deploy a SDN-C high availability environment - Kubernetes <https://jira.onap.org/browse/SDNC-163>           |
153 +------------+-------------------------------------------------------------------------------------------------------------+
154
155
156 **Bug Fixes**
157
158 The list of bugs fixed in the SDNC Beijing release may be found in the ONAP Jira at <https://jira.onap.org/issues/?filter=11118>
159
160
161 **Known Issues**
162
163 +------------+----------------------------------------------------------------------------------------------------------------------------------+
164 | Jira #     | Abstract                                                                                                                         |
165 +============+==================================================================================================================================+
166 | [SDNC-324] | IPV4_ADDRESS_POOL is empty <https://jira.onap.org/browse/SDNC-324>                                                               |
167 +------------+----------------------------------------------------------------------------------------------------------------------------------+
168 | [SDNC-321] | dgbuilder won't save DG <https://jira.onap.org/browse/SDNC-321>                                                                  |
169 +------------+----------------------------------------------------------------------------------------------------------------------------------+
170 | [SDNC-304] | SDNC OOM intermittent Healthcheck failure - JSONDecodeError - on different startup order <https://jira.onap.org/browse/SDNC-304> |
171 +------------+----------------------------------------------------------------------------------------------------------------------------------+
172 | [SDNC-115] | VNFAPI DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-115>                        |
173 +------------+----------------------------------------------------------------------------------------------------------------------------------+
174 | [SDNC-114] | Generic API DGs contain plugin references to software not part of ONAP <https://jira.onap.org/browse/SDNC-114>                   |
175 +------------+----------------------------------------------------------------------------------------------------------------------------------+
176 | [SDNC-106] | VNFAPI DGs contain old openecomp and com.att based plugin references <https://jira.onap.org/browse/SDNC-106>                     |
177 +------------+----------------------------------------------------------------------------------------------------------------------------------+
178 | [SDNC-64]  | SDNC is not setting FromApp identifier in logging MDC <https://jira.onap.org/browse/SDNC-64>                                     |
179 +------------+----------------------------------------------------------------------------------------------------------------------------------+
180
181
182 **Security Notes**
183
184 SDNC code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The SDNC open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_.
185
186 Quick Links:
187
188 - `SDNC project page <https://wiki.onap.org/display/DW/Software+Defined+Network+Controller+Project>`_
189 - `Passing Badge information for SDNC <https://bestpractices.coreinfrastructure.org/en/projects/1703>`_
190 - `Project Vulnerability Review Table for SDNC <https://wiki.onap.org/pages/viewpage.action?pageId=28379582>`_
191
192 **Upgrade Notes**
193         NA
194
195 **Deprecation Notes**
196         NA
197
198 **Other**
199         NA
200
201 Version: 1.2.1
202 --------------
203
204 :Release Date: 2018-01-18
205
206 **Bug Fixes**
207
208 - `SDNC-145 <https://jira.onap.org/browse/SDNC-145>`_ Error message refers to wrong parameters
209 - `SDNC-195 <https://jira.onap.org/browse/SDNC-195>`_ UEB listener doesn't insert correct parameters for allotted resources in DB table ALLOTTED_RESOURCE_MODEL
210 - `SDNC-198 <https://jira.onap.org/browse/SDNC-198>`_ CSIT job fails
211 - `SDNC-201 <https://jira.onap.org/browse/SDNC-201>`_ Fix DG bugs from integration tests
212 - `SDNC-202 <https://jira.onap.org/browse/SDNC-202>`_ Search for service -data null match, set vGW LAN IP via Heat
213 - `SDNC-211 <https://jira.onap.org/browse/SDNC-211>`_ Update SDNC Amsterdam branch to use maintenance release versions
214 - `SDNC-212 <https://jira.onap.org/browse/SDNC-212>`_ Duplicate file name
215
216 Version: 1.2.0
217 --------------
218
219 :Release Date: 2017-11-16
220
221 **New Features**
222
223 The ONAP Amsterdam release introduces the following changes to SDNC from
224 the original openECOMP seed code:
225    - Refactored / moved common platform code to new CCSDK project
226    - Refactored code to rename openecomp to onap
227    - Introduced new GENERIC-RESOURCE-API api, used by vCPE and VoLTE use cases
228    - Introduced new docker containers for SDC and DMAAP interfaces
229
230 **Bug Fixes**
231         NA
232 **Known Issues**
233 The following known high priority issues are being worked and are expected to be delivered
234 in release 1.2.1:
235 - `SDNC-179 <https://jira.onap.org/browse/SDNC-179>`_ Failed to make HTTPS connection in restapicall node
236 - `SDNC-181 <https://jira.onap.org/browse/SDNC-181>`_ Change call to brg-wan-ip-address vbrg-wan-ip brg topo activate DG
237 - `SDNC-182 <https://jira.onap.org/browse/SDNC-182>`_ Fix VNI Consistency: Add vG vxlan tunnel setup and bridge domain setup to brg-topo-activate DG
238
239 **Security Issues**
240         NA
241
242 **Upgrade Notes**
243         NA
244
245 **Deprecation Notes**
246         NA
247
248 **Other**
249         NA