[ANNOUNCEMENT] Apache BVal 2.0.4 Released

2020-07-14 Thread Thomas Andraschko
The Apache BVal team is pleased to announce the release of: Apache BVal 2.0.4 Apache BVal delivers an implementation of the Java Bean Validation specification 2.0. The following changes are included in this release: BVal now provides a shaded jar with jakarta.* packages via dependency qualifier

[SECURITY] CVE-2020-13935 Apache Tomcat WebSocket Denial of Service

2020-07-14 Thread Mark Thomas
CVE-2020-13935 Apache Tomcat WebSocket Denial of Service Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0-M6 Apache Tomcat 9.0.0.M1 to 9.0.36 Apache Tomcat 8.5.0 to 8.5.56 Apache Tomcat 7.0.27 to 7.0.104 Description: The payload len

[SECURITY] CVE-2020-13934 Apache Tomcat HTTP/2 Denial of Service

2020-07-14 Thread Mark Thomas
CVE-2020-13934 Apache Tomcat HTTP/2 Denial of Service Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0-M6 Apache Tomcat 9.0.0.M5 to 9.0.36 Apache Tomcat 8.5.1 to 8.5.56 Description: An h2c direct connection did not release the HTTP/1

[SECURITY][CVE-2020-13925] Apache Kylin command injection vulnerability

2020-07-14 Thread ShaoFeng Shi
Versions Affected: 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1 3.0.2 Description: Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS com

[SECURITY][CVE-2020-13926] Apache Kylin SQL injection vulnerability

2020-07-14 Thread ShaoFeng Shi
Versions Affected: 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1 3.0.2 Description: Kylin concatenates and executes some Hive SQL statements in Hive CLI or beeline w