[ANN] Apache Tomcat 8.5.91 available

2023-07-10 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.91. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.91 is a bugfix and

[ANN] Apache Tomcat 10.1.11 available

2023-07-10 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.11. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations

[ANNOUNCE] Airflow Providers prepared on July 09, 2023 are released

2023-07-10 Thread Elad Kalif
Dear community, I'm happy to announce that new versions of Airflow Providers packages were just released. https://pypi.org/project/apache-airflow-providers-amazon/8.3.0/ The source release, as well as the binary releases, are available here:

[ANN] Apache Tomcat 9.0.78 available

2023-07-10 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.78. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.78 is a bugfix and

[ANNOUNCE] Apache JMeter 5.6.1 released

2023-07-10 Thread Milamber
The Apache JMeter team is pleased to announce the availability of Apache JMeter 5.6.1 (9f803e313a). This release brings improvements, and also fixes bugs. You can read the New and Noteworthy section to view improvements and full list of changes at: https://jmeter.apache.org/changes.html

CVE-2022-45855: Apache Ambari: Allows authenticated metrics consumers to perform RCE

2023-07-10 Thread Brahma Reddy Battula
Affected versions: - Apache Ambari 2.7.0 through 2.7.6 Description: SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely.  Users are recommended to upgrade to 2.7.7. Credit: rg

CVE-2022-42009: Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.

2023-07-10 Thread Brahma Reddy Battula
Affected versions: - Apache Ambari 2.7.0 through 2.7.6 Description: SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. Credit: Jecki Go

[ANN] Apache Syncope 3.0.4

2023-07-10 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 3.0.4 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning,

[ANNOUNCE] Apache Pulsar Go Client 0.11.0 released

2023-07-10 Thread Zike Yang
The Apache Pulsar team is proud to announce Apache Pulsar Go Client version 0.11.0. Pulsar is a highly scalable, low latency messaging platform running on commodity hardware. It provides simple pub-sub semantics over topics, guaranteed at-least-once delivery of messages, automatic cursor

[ANNOUNCE] Apache Pulsar Node.js client 1.9.0 released

2023-07-10 Thread Baodi Shi
The Apache Pulsar team is proud to announce Apache Pulsar Node.js client version 1.9.0. Pulsar is a highly scalable, low latency messaging platform running on commodity hardware. It provides simple pub-sub semantics over topics, guaranteed at-least-once delivery of messages, automatic cursor

[ANN] Apache Struts 6.2.0

2023-07-10 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 6.2.0 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2023#a20230710 Below is a full list of all changes. Bug WW-4434 - datetextfield.ftl is

[ANNOUNCE] Apache Uniffle (Incubating) 0.7.1 available

2023-07-10 Thread Jiafu Zhang
Hi all, Apache Uniffle (Incubating) Team is glad to announce the new release of Apache Uniffle (Incubating) 0.7.1. Apache Uniffle (Incubating) builds a computation middleware layer to decouple the upper applications and the underlying data engines, provides standardized interfaces (REST, JDBC,

[ANNOUNCE] Airflow Providers prepared on July 06, 2023 are released

2023-07-10 Thread Elad Kalif
Dear community, I'm happy to announce that new versions of Airflow Providers packages were just released. https://pypi.org/project/apache-airflow-providers-alibaba/2.5.0/ https://pypi.org/project/apache-airflow-providers-apache-hive/6.1.2/

[ANNOUNCE] Apache DataFu-Spark 1.8.0 Released

2023-07-10 Thread Eyal Allweil
Dear community, I'm happy to announce that DataFu-Spark 1.8.0 was just released. The mission of DataFu is to help developers solve common data problems in the Hadoop eco-system. This new release contains some minor improvements and deprecates support for some older versions of Spark. You can

CVE-2023-35887: Apache MINA SSHD: Information disclosure bugs with RootedFilesystem

2023-07-10 Thread Guillaume Nodet
Affected versions: - Apache MINA SSHD 1.0 before 2.10 Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to