The Apache News Round-up: week ending 13 August 2021

2021-08-13 Thread Swapnil M Mane
[this newsletter is available online at https://s.apache.org/pzpb0 ] We're wrapping up another great week with the following activities from the Apache community: ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws. - Next

CVE-2021-35936: Apache Airflow: No Authentication on Logging Server

2021-08-13 Thread Kaxil Naik
Description: If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no authentication and allows