<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 19:55:01 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[CONTROLLER-1235] odl-mdsal-apidocs feature is not protected through AAA</title>
                <link>https://jira.opendaylight.org/browse/CONTROLLER-1235</link>
                <project id="10113" key="CONTROLLER">controller</project>
                    <description>&lt;p&gt;The URLS supported by the odl-mdsal-apidocs are not protected by the controller&apos;s AAA.  This is a security vulnerability when the security model prohibits any access to the controller without authentication.&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="25789">CONTROLLER-1235</key>
            <summary>odl-mdsal-apidocs feature is not protected through AAA</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10000">Done</resolution>
                                        <assignee username="-1">Unassigned</assignee>
                                    <reporter username="rgoulding">Ryan Goulding</reporter>
                        <labels>
                    </labels>
                <created>Thu, 2 Apr 2015 14:14:33 +0000</created>
                <updated>Tue, 25 Jul 2023 08:23:59 +0000</updated>
                            <resolved>Tue, 5 May 2015 15:34:57 +0000</resolved>
                                                                    <component>restconf</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                                                                <comments>
                            <comment id="50365" author="rgoulding" created="Fri, 3 Apr 2015 17:26:11 +0000"  >&lt;p&gt;The fix for this Bug was tested by:&lt;/p&gt;

&lt;p&gt;1) Running karaf &lt;br/&gt;
cd controller&lt;br/&gt;
./opendaylight/distribution/opendaylight-karaf/target/assembly/bin/karaf debug&lt;/p&gt;

&lt;p&gt;2) feature:install odl-restconf odl-mdsal-apidocs&lt;/p&gt;

&lt;p&gt;3) Visiting the api explorer web page, and ensuring that the page is not loaded until valid AuthN was supplied.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://localhost:8181/apidoc/explorer/index.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://localhost:8181/apidoc/explorer/index.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This test was done using:&lt;br/&gt;
1) Google Chrome Version 41.0.2272.101 (64-bit)&lt;br/&gt;
2) Mozilla Firefox Version 36.0.4&lt;br/&gt;
On Fedora 20 with kernel &quot;Linux fedora 3.18.9-100.fc20.x86_64&quot;.&lt;/p&gt;</comment>
                            <comment id="50366" author="carolsand@gmail.com" created="Tue, 5 May 2015 15:17:26 +0000"  >&lt;p&gt;This bug is part of the project to Move all ADSAL associated component bugs to ADSAL.&lt;/p&gt;</comment>
                            <comment id="50367" author="rgoulding" created="Tue, 5 May 2015 15:34:57 +0000"  >&lt;p&gt;This is not an ADSAL bug.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>2942</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=2942]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10206" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Issue Type</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10300"><![CDATA[Bug]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10204" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>ODL SR Target Milestone</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10315"><![CDATA[Lithium]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                    <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i02pbj:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>