[ANNOUNCE] Apache Calcite Avatica 1.20.0 released

2021-12-13 Thread Julian Hyde
The Apache Calcite team is pleased to announce the release of Apache Calcite Avatica 1.20.0. Avatica is a framework for building database drivers. Avatica defines a wire API and serialization mechanism for clients to communicate with a server as a proxy to a database. The reference Avatica client

[ANNOUNCE] Apache Log4j 2.16.0 Released

2021-12-13 Thread Matt Sicker
The Apache Log4j 2 team is pleased to announce the Log4j 2.16.0 release! Apache Log4j is a well known framework for logging application behavior. Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many other modern features such as

[ANNOUNCE] Apache OFBiz 18.12.03 released

2021-12-13 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.03". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.03" is the

CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2

2021-12-13 Thread Ralph Goers
Description: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests

[ANNOUNCEMENT] HttpComponents HttpAsyncClient 4.1.5 GA Released

2021-12-13 Thread Oleg Kalnichevski
The Apache HttpComponents project is pleased to announce 4.1.5 GA release of HttpComponents HttpAsyncClient. This is a maintenance release that fixes a number of issues discovered since 4.1.4. --- Download - Release notes - <