[ANN] Apache Syncope 2.1.7

2020-09-14 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.1.7 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads

[ANN] Apache Syncope 2.0.16

2020-09-14 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.0.16 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads

[CVE-2020-11977] Apache Syncope: Remote Code Execution via Flowable workflow definition

2020-09-14 Thread Francesco Chicchiriccò
Description: When the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution. Severity: Low Vendor: The Apache Software Foundation Affects: 2.

[ANNOUNCEMENT] HttpComponents Core 5.0.2 GA released

2020-09-14 Thread Oleg Kalnichevski
The Apache HttpComponents project is pleased to announce 5.0.2 GA release of HttpComponents Core. This release reverts changes to early response handling logic introduced in 5.0.1 and fixes a number of minor defects. Improvement of the early response handling by the classic client protocol handle

[ANNOUNCEMENT] Commons Daemon 1.2.3 Released

2020-09-14 Thread Mark Thomas
The Apache Commons Team is pleased to announce the availability of Apache Commons Daemon 1.2.3. The Apache Commons Daemon software library provides a generic Daemon (unix) or Service (Windows) wrapper for Java code. Version 1.2.3 is a bugfix release. A full list of changes can be found at http