[ANNOUNCE] Apache OpenMeetings 6.3.0 is released

2022-05-17 Thread Maxim Solodovnik
he Apache OpenMeetings project is pleased to announce the release of Apache OpenMeetings 6.3.0. The release is available for download from https://openmeetings.apache.org/downloads.html Openmeetings provides video conferencing, instant messaging, white board, collaborative document editing and

CVE-2022-25169: Apache Tika BPGParser Memory Usage DoS

2022-05-17 Thread Tim Allison
Description: The BPG parser in versions of Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

[ANNOUNCE] New Airflow Providers released on Mon, 16 May, 2022

2022-05-17 Thread Jarek Potiuk
Dear community, I'm happy to announce that new versions of Airflow Providers packages were just released. The mission of Apache Airflow is the creation and maintenance of software related to workflow automation and scheduling that can be used to author and manage data pipelines. Airflow

CVE-2022-26650: Apache ShenYu (incubating) Regular expression denial of service

2022-05-17 Thread Zhang Yonglun
Severity: moderate Description: In ShenYu-Bootstrap there's RegexPredicateJudge.java which uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and

[ANNOUNCE] Apache ServiceComb Pack version 0.7.0 Released

2022-05-17 Thread Lei Zhang
Hello All, Apache ServiceComb Team is glad to announce the release of Apache ServiceComb Pack 0.7.0 Apache ServiceComb Pack(https://github.com/apache/servicecomb-pack) is an eventually data consistency solution for micro-service applications. ServiceComb Pack currently has TCC and Saga