CVE-2022-25312: An XML external entity (XXE) injection vulnerability exists in the Apache Any23 RDFa XSLTStylesheet extractor

2022-03-04 Thread lewis john mcgibbney
Description: An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an

[ANNOUNCE] Apache Any23 2.7

2022-03-04 Thread lewis john mcgibbney
The Apache Any23 Project Management Committee is pleased to announce the release of Apache Any23 2.7. Apache Anything To Triples (Any23) is a library, a web service and a command line tool that extracts structured data in RDF format from a variety of Web documents. Any23 2.7 requires JDK11 to

[ANNOUNCE] Apache NetBeans 13 released

2022-03-04 Thread Geertjan Wielenga
Hi all, The Apache NetBeans team is pleased to announce that Apache NetBeans 13 is released today on March 4, 2022. Apache NetBeans is a full IDE for Java SE, Java EE, PHP, JavaScript, HTML5 and more, including some support for Groovy and C/C++. Our schedule is publicly available here:

The Apache Weekly News Round-up: week ending 4 March 2022

2022-03-04 Thread Sally Khudairi
We're opening March with a cracking week. Here's what the Apache community has been up to: Sponsor Apache – a number of tax-deductible sponsorships help offset the ASF's day-to-day operating expenses that include infrastructure support, bandwidth, connectivity, servers, hardware, development

CVE-2022-26336: poi-scratchpad: A carefully crafted TNEF file can cause an out of memory exception

2022-03-04 Thread PJ Fanning
Severity: moderate Description: A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse

[ANNOUNCE] Apache POI 5.2.1 released

2022-03-04 Thread PJ Fanning
The Apache POI project is pleased to announce the release of POI 5.2.1. Featured are a handful of new areas of functionality, and numerous bug fixes. See the downloads page for binary and source distributions: https://poi.apache.org/download.html Release Notes Changes The most