[CVE-2021-30128] Unsafe deserialization in OFBiz

2021-04-27 Thread jler...@apache.org
Severity: High, possible RCE Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 17.12.07 Description: Apache OFBiz has unsafe deserialization prior to 17.12.07 version Mitigation: Upgrade to at least 17.12.07 or apply patches at

[CVE-2021-29200] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

2021-04-27 Thread jler...@apache.org
Severity: High, possible RCE Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 17.12.07 Description: Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform a RCE attack Mitigation: Upgrade to at least 17.12.07 or

Re: [ANNOUNCE] Apache OFBiz 17.12.07 released

2021-04-27 Thread Nicolas Malin
Thanks Jacopo for the works Cheers, Nicolas On 27/04/2021 11:52, Jacopo Cappellato wrote: > The Apache OFBiz community is pleased to announce the new release "Apache > OFBiz 17.12.07". > > Apache OFBiz® is an open source product for the automation of enterprise > processes that includes

[ANNOUNCE] Apache OFBiz 17.12.07 released

2021-04-27 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.07". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.07" is the

Fwd: [Action Required]: Linked domain Status Pages no longer supported in Free Plan

2021-04-27 Thread Jacques Le Roux
FYI: anyway it was not reliable Jacques Message transféré Sujet : [Action Required]: Linked domain Status Pages no longer supported in Free Plan Date : Tue, 27 Apr 2021 08:42:42 + De :UptimeRobot UptimeRobot Visit website