[ANNOUNCE] Apache Beam 2.37.0 Released

2022-03-14 Thread Brian Hulette
The Apache Beam team is pleased to announce the release of version 2.37.0. Apache Beam is an open source unified programming model to define and execute data processing pipelines, including ETL, batch and stream (continuous) processing. See https://beam.apache.org You can download the release

[ANN] Apache Tomcat 9.0.60 available

2022-03-14 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.60. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.60 is a bugfix and

[ANN] Apache Tomcat 10.0.18 available

2022-03-14 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.0.18. This release is targeted at Jakarta EE 9. Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 without changes. Java EE applications designed for Tomcat 9 and earlier may be placed in the

CVE-2022-22721: Apache HTTP Server: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody

2022-03-14 Thread Stefan Eissing
Severity: low Description: If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. Credit: Anonymous working with

[ANN] Apache Tomcat 10.1.0-M12 (alpha) available

2022-03-14 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.0-M12 (alpha). Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations

CVE-2022-22719: Apache HTTP Server: mod_lua Use of uninitialized value of in r:parsebody

2022-03-14 Thread Stefan Eissing
Severity: moderate Description: A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. Credit: Chamal De Silva

CVE-2022-22720: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

2022-03-14 Thread Stefan Eissing
Severity: important Description: Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling Credit: James Kettle

CVE-2022-23943: Apache HTTP Server: mod_sed: Read/write beyond bounds

2022-03-14 Thread Stefan Eissing
Severity: important Description: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. Credit: Ronald Crane (Zippenhop

[ANNOUNCE] Apache Groovy 4.0.1 Released

2022-03-14 Thread Paul King
Dear community, The Apache Groovy team is pleased to announce version 4.0.1 of Apache Groovy. Apache Groovy is a multi-faceted programming language for the JVM. Further details can be found at the https://groovy.apache.org website. This release is a maintenance release of the GROOVY_4_0_X

[ANNOUNCE] Apache Libcloud 3.5.0 release

2022-03-14 Thread Tomaz Muraus
Libcloud is a Python library that abstracts away the differences among multiple cloud provider APIs. It allows users to manage cloud services (servers, storage, load balancers, DNS, containers as a service) offered by many different providers through a single, unified and easy to use API. We are

[ANNOUNCE] Apache Kafka 3.0.1

2022-03-14 Thread Mickael Maison
The Apache Kafka community is pleased to announce the release for Apache Kafka 3.0.1 Apache Kafka 3.0.1 is a bugfix release and 29 issues have been fixed since 3.0.0. All of the changes in this release can be found in the release notes: https://www.apache.org/dist/kafka/3.0.1/RELEASE_NOTES.html

[ANNOUNCEMENT] Apache HTTP Server 2.4.53 Released

2022-03-14 Thread icing
Apache HTTP Server 2.4.53 Released March 14, 2022 The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.4.53 of the Apache HTTP Server ("Apache"). This version of Apache is our latest GA release of the

[ANNOUNCE] Apache Camel 3.11.6 (LTS) Released

2022-03-14 Thread Gregor Zurowski
The Camel PMC is pleased to announce the release of Apache Camel 3.11.6 (LTS). Apache Camel is an open source integration framework that empowers you to quickly and easily integrate various systems consuming or producing data. This patch release contains 23 bug fixes and improvements. The