[CVE-2020-1931] Apache SpamAssassin Nefarious rule configuration (.cf) files can be configured to run system commands with warnings.

2020-01-29 Thread Kevin A. McGrail
Apache SpamAssassin 3.4.4 was recently released [1], and fixes an issue of security note where nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805.  This issue is less stealthy and attempts to exploit the issue will throw warnings.  Thanks to

[ANNOUNCE] Apache Libcloud 3.0.0-rc1 release

2020-01-29 Thread Tomaz Muraus
Libcloud is a Python library that abstracts away the differences among multiple cloud provider APIs. It allows users to manage cloud services (servers, storage, load balancers, DNS, containers as a service) offered by many different providers through a single, unified and easy to use API. We are

ANNOUNCE: Apache SpamAssassin 3.4.4 available

2020-01-29 Thread Kevin A. McGrail
On behalf of the Apache SpamAssassin Project, I am pleased to announce version 3.4.4 is available. Release Notes -- Apache SpamAssassin -- Version 3.4.4 Introduction Apache SpamAssassin 3.4.4 is primarily a security release. In this release, there are bug fixes for two CVEs. ***

[ANNOUNCE] Beam 2.18.0 Released

2020-01-29 Thread Udi Meiri
The Apache Beam team is pleased to announce the release of version 2.18.0. Apache Beam is an open source unified programming model to define and execute data processing pipelines, including ETL, batch and stream (continuous) processing. See https://beam.apache.org You can download the release

[ANNOUNCE] Apache Jackrabbit Oak 1.10.8 released

2020-01-29 Thread Julian Reschke
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit Oak 1.10.8. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit

[ANNOUNCE] Apache Jackrabbit Oak 1.24.0 released

2020-01-29 Thread Julian Reschke
From: ${username}@apache.org To: announce@apache.org, annou...@jackrabbit.apache.org, us...@jackrabbit.apache.org, d...@jackrabbit.apache.org, oak-...@jackrabbit.apache.org Subject: [ANNOUNCE] Apache Jackrabbit Oak 1.24.0 released The Apache Jackrabbit community is pleased to announce the

[ANNOUNCE] Apache OpenWebBeans-2.0.14 released

2020-01-29 Thread Mark Struberg
It’s a great pleasure to announce the release of Apache OpenWebBeans-2.0.14 Apache OpenWebBeans-2.x is a CDI container (Contexts and Dependency Injection for Java) and targets the CDI-2.0 specification (JavaEE 8). This is a maintenance release targeting the new CDI 2.0 specification! CDI is a