[Apache CXF] CVE-2021-22696: OAuth 2 authorization service vulnerable to DDos attacks

2021-04-02 Thread Colm O hEigeartaigh
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI

[ANN] Apache Karaf runtime 4.3.1 has been released!

2021-04-02 Thread Jean-Baptiste Onofré
The Apache Karaf team is pleased to announce Apache Karaf runtime 4.3.1 release. This release is a major release on the Karaf 4.3.x series, bringing updates, fixes and new features, especially: - java.* now exported by system packages (as expected since R7) - fixed on configuration with json

The Apache News Round-up: week ending 2 April 2021

2021-04-02 Thread Swapnil M Mane
[this newsletter is available online at https://s.apache.org/75r6y ] Welcome, April --we're opening the month with another great week. Here's what the Apache community has been up to: Apache Month-in-Review – a look back at our activities over the past month. - March 2021