[ANNOUNCE] Apache Wicket 8.15.0 released

2023-05-02 Thread Andrea Del Bene
The Apache Wicket PMC is proud to announce Apache Wicket 8.15.0! Apache Wicket is an open source Java component oriented web application framework that powers thousands of web applications and web sites for governments, stores, universities, cities, banks, email providers, and more. You can find

CVE-2023-26268: Apache CouchDB, IBM Cloudant: Information sharing via couchjs processes

2023-05-02 Thread Nick Vatamaniuc
Affected versions: - Apache CouchDB through 3.3.1 - IBM Cloudant through 8349 Description: Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions: * validate_doc_update *

CVE-2023-32007: Apache Spark: Shell command injection via Spark UI

2023-05-02 Thread Arnout Engelen
Severity: important Affected versions: - Apache Spark 3.1.1 before 3.2.2 Description: ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access

[ANNOUNCE] Apache BookKeeper 4.16.1 released

2023-05-02 Thread Hang Chen
The Apache BookKeeper team is proud to announce Apache BookKeeper version 4.16.1. Apache BookKeeper is a scalable, fault-tolerant, and low-latency storage service optimized for real-time workloads. It has been used for a fundamental service to build reliable services. It is also the log segment

[ANNOUNCE] Apache BookKeeper 4.16.0 released

2023-05-02 Thread Hang Chen
The Apache BookKeeper team is proud to announce Apache BookKeeper version 4.16.0. Apache BookKeeper is a scalable, fault-tolerant, and low-latency storage service optimized for real-time workloads. It has been used for a fundamental service to build reliable services. It is also the log segment