Apache Month in Review: February 2021

2021-03-01 Thread Sally Khudairi
[this announcement is available online at https://s.apache.org/Feb2021 ] Welcome to the latest monthly overview of events from the Apache community. Here's a summary of what happened in February: New this month -- - Call for Apache project proposals and mentors: Outreachy Open Source internshi

[SECURITY] CVE-2021-25122 Apache Tomcat h2c request mix-up

2021-03-01 Thread Mark Thomas
CVE-2021-25122 h2c request mix-up Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0 Apache Tomcat 9.0.0.M1 to 9.0.41 Apache Tomcat 8.5.0 to 8.5.61 Description: When responding to new h2c connection requests, Apache Tomcat could dup

[SECURITY] CVE-2021-25329 Apache Tomcat Incomplete fix for CVE-2020-9484 (RCE via session persistence)

2021-03-01 Thread Mark Thomas
CVE-2021-25329 Incomplete fix for CVE-2020-9484 (RCE via session persistence) Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0 Apache Tomcat 9.0.0.M1 to 9.0.41 Apache Tomcat 8.5.0 to 8.5.61 Apache Tomcat 7.0.0 to 7.0.107 Description: T

[ANNOUNCE] Apache NiFi MiNiFi C++ 0.9.0 release

2021-03-01 Thread Marton Szasz
Hello The Apache NiFi team would like to announce the release of Apache NiFi MiNiFi C++ 0.9.0. Highlights of the 0.9.0 release include: - Added support for RocksDB-based content repository for better performance - Added SQL extension - Improved task scheduling - Various C2 improvements - Bug

[ANNOUNCE] Release Apache SkyWalking Nginx LUA version 0.4.0

2021-03-01 Thread Daming
Hi all, Apache SkyWalking Team is glad to announce the first release of Apache SkyWalking Nginx LUA 0.4.0 SkyWalking: APM (application performance monitor) tool for distributed systems, especially designed for microservices, cloud-native and container-based (Docker, Kubernetes, Mesos) architectu