The Apache News Round-up: week ending 13 March 2020

2020-03-13 Thread Swapnil M Mane
[this newsletter is available online at https://s.apache.org/hn3q4 ] Greetings everyone --it's time to review the Apache community's activities from the past week: The Apache Software Foundation Statement on the COVID-19 Coronavirus Outbreak https://s.apache.org/COVID-19 Apache Month In Review

[CVE-2019-10091] Apache Geode SSL endpoint verification vulnerability

2020-03-13 Thread Anthony Baker
CVE-2019-10091 Apache Geode SSL endpoint verification vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Geode 1.9.0 Description: When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname