CVE-2023-49070: Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

2023-12-04 Thread Jacques Le Roux
Severity: moderate Affected versions: - Apache OFBiz before 18.12.10 Description: Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10 This issue i

[ANNOUNCE] Apache OFBiz 18.12.10 released

2023-12-04 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.10". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.10" is the tent

[VOTE] [RESULT] Apache OFBiz 18.12.10

2023-12-04 Thread Jacopo Cappellato
The vote was successful with 8 positive votes (of which 6 are binding) and no negative votes. Thank you, Jacopo

Re: [VOTE] Apache OFBiz 18.12.10

2023-12-04 Thread Jacopo Cappellato
+1 Jacopo On Mon, Nov 27, 2023 at 11:48 AM Jacopo Cappellato wrote: > > This is the vote thread to publish "Apache OFBiz 18.12.10", tenth > release from the release18.12 branch. > > The release files can be downloaded from here: > https://dist.apache.org/repos/dist/dev/ofbiz/ > and are: > * apac