From 5ed5c26fe0d9a2803101498d7a500f206960632d Mon Sep 17 00:00:00 2001 From: Krzysztof Opasiak Date: Thu, 6 Jun 2019 01:13:13 +0200 Subject: [PATCH] Document OJSI-42 (CVE-201912123) vulnerability Issue-ID: OJSI-42 Signed-off-by: Krzysztof Opasiak Change-Id: I9f9a475c3926c4eb462070b16ade2a3a947fc33d Former-commit-id: 40bd3f09e43fa80097268230b5432e7a55b8b715 --- docs/release-notes.rst | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/release-notes.rst b/docs/release-notes.rst index 40192add..bdafa1cb 100644 --- a/docs/release-notes.rst +++ b/docs/release-notes.rst @@ -42,6 +42,8 @@ The full list of known issues in SDNC may be found in the ONAP Jira at `_ SDNC service allows for arbitrary code execution in sla/dgUpload form Fixed temporarily by disabling admportal +- CVE-2019-12123 `OJSI-42 `_ SDNC service allows for arbitrary code execution in sla/printAsXml form + Fixed temporarily by disabling admportal *Known Security Issues* -- 2.16.6