CVE-2023-28706: Apache Airflow Hive Provider Beeline Remote Command Execution

2023-04-07 Thread Jarek Potiuk
Severity: low Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0. Credit: sw0rd1ight of Caiji Sec Team and 4ra1n of Chaitin Tech (finder)

CVE-2023-28710: Apache Airflow Spark Provider Arbitrary File Read via JDBC

2023-04-07 Thread Jarek Potiuk
Severity: low Description: Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1. Credit: Xie Jianming of Nsfocus (finder) References: https://github.com/apache/airflow/pull/30223

CVE-2023-28707: Airflow Apache Drill Provider Arbitrary File Read Vulnerability

2023-04-07 Thread Jarek Potiuk
Severity: low Description: Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. Credit: Kai Zhao of 3H Secruity Team (finder) References:

[ANNOUNCE] Apache NiFi 1.21.0 release.

2023-04-07 Thread Joe Witt
Hello The Apache NiFi team would like to announce the release of Apache NiFi 1.21.0. Apache NiFi is an easy to use, powerful, and reliable system to process and distribute data. Apache NiFi was made for dataflow. It supports highly configurable directed graphs of data routing, transformation,

[ANNOUNCEMENT] Apache HTTP Server 2.4.57 Released

2023-04-07 Thread covener
Apache HTTP Server 2.4.57 Released April 06, 2023 The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.4.57 of the Apache HTTP Server ("Apache"). This version of Apache is our latest GA release of the

[ANNOUNCE] Apache Linkis 1.3.2 available

2023-04-07 Thread Ling Xu
Hi all, Apache Linkis Team is glad to announce the new release of Apache Linkis 1.3.2. Apache Linkis builds a computation middleware layer to decouple the upper applications and the underlying data engines, provides standardized interfaces (REST, JDBC, WebSocket etc.) to easily connect to