[ANNOUNCE] Apache Ignite 2.14.0 Released

2022-10-11 Thread Taras Ledkov
The Apache Ignite Community is pleased to announce the release of Apache Ignite 2.14.0. Apache Ignite® is an in-memory computing platform for transactional, analytical, and streaming workloads delivering in-memory speeds at a petabyte scale. https://ignite.apache.org For the full list of

[ANN] Apache Tomcat 8.5.83 available

2022-10-11 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.83. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.83 is a bugfix and

[ANNOUNCE] Apache Commons RNG 1.5 released

2022-10-11 Thread Alex Herbert
The Apache Commons Team is pleased to announce the availability of version 1.5 of "Apache Commons RNG". Apache Commons RNG provides Java implementations of pseudo-random numbers generators. Changes in this version include: New features: o RNG-182: Add a Bill of Materials (BOM) to aid in

CVE-2022-24697: Apache Kylin: Command injection exists when the configuration overwrites function overwrites system parameters

2022-10-11 Thread Xiaoxiang Yu
Severity: important Description: Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any

[ANN] Apache Tomcat 10.1.1 available

2022-10-11 Thread Mark Thomas
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.1. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations