Document OJSI-41 (CVE-2019-12132) vulnerability 47/89447/1
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 23:01:02 +0000 (01:01 +0200)
committerKrzysztof Opasiak <k.opasiak@samsung.com>
Wed, 5 Jun 2019 23:22:59 +0000 (01:22 +0200)
Issue-ID: OJSI-41
Signed-off-by: Krzysztof Opasiak <k.opasiak@samsung.com>
Change-Id: I9d80043c3f8dc9d2f30d178b34e11ff1d0c366ea

Former-commit-id: e02a73b130b8caa37dde3c0d824492246bf24447

docs/release-notes.rst

index f4ea951..40192ad 100644 (file)
@@ -40,6 +40,9 @@ The full list of known issues in SDNC may be found in the ONAP Jira at <https://
 
 *Fixed Security Issues*
 
+- CVE-2019-12132 `OJSI-41 <https://jira.onap.org/browse/OJSI-41>`_ SDNC service allows for arbitrary code execution in sla/dgUpload form
+  Fixed temporarily by disabling admportal
+
 *Known Security Issues*
 
 *Known Vulnerabilities in Used Modules*
@@ -240,5 +243,3 @@ in release 1.2.1:
 
 **Other**
        NA
-
-