[ANN] Apache OpenJPA 4.0.1
The Apache OpenJPA team is pleased to announce the release of OpenJPA 4.0.1 Apache OpenJPA is a persistent object management kernel for databases, relational as well as non-relational. For relational databases, OpenJPA is compliant to the Jakarta Persistence API 3.0. OpenJPA runs in stand-alone Java SE as well as containers e.g Jakarta EE, Tomcat, Spring or OSGi. The release will be available within 24h from Central Maven Repository and: https://openjpa.apache.org/downloads Read the full change log available here: https://s.apache.org/openjpa401 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at https://openjpa.apache.org/ The Apache OpenJPA Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 3.0.8
The Apache Syncope team is pleased to announce the release of Syncope 3.0.8 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope308 Upgrading from 3.0.5? There are some notes about this process: https://s.apache.org/2jwk4 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
CVE-2024-38503: Apache Syncope: HTML tags can be injected into Console or Enduser text fields
Severity: moderate Affected versions: - Apache Syncope 2.1 through 2.1.14 - Apache Syncope 3.0 through 3.0.7 Description: When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue. Credit: Basalt IT-Security Team (finder) References: https://syncope.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-38503
[ANN] Apache Syncope 3.0.7
The Apache Syncope team is pleased to announce the release of Syncope 3.0.7 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope307 Upgrading from 3.0.5? There are some notes about this process: https://s.apache.org/llrmu We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 3.0.6
The Apache Syncope team is pleased to announce the release of Syncope 3.0.6 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope306 Upgrading from 3.0.5? There are some notes about this process: https://s.apache.org/0ytql We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 3.0.5
The Apache Syncope team is pleased to announce the release of Syncope 3.0.5 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope305 Upgrading from 3.0.4? There are some notes about this process: https://s.apache.org/3pjc8 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.4
The Apache Syncope team is pleased to announce the release of Syncope 3.0.4 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope304 Upgrading from 3.0.3? There are some notes about this process: https://s.apache.org/a0bl5 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.14
The Apache Syncope team is pleased to announce the release of Syncope 2.1.14 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2114 Upgrading from 2.1.13? There are some notes about this process: https://s.apache.org/uhxpz We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.3
The Apache Syncope team is pleased to announce the release of Syncope 3.0.3 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope303 Upgrading from 3.0.2? There are some notes about this process: https://s.apache.org/fto4b We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.2
The Apache Syncope team is pleased to announce the release of Syncope 3.0.2 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope302 Upgrading from 3.0.1? There are some notes about this process: https://s.apache.org/ool4w We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.1
The Apache Syncope team is pleased to announce the release of Syncope 3.0.0 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope301 Upgrading from 3.0.0? There are some notes about this process: https://s.apache.org/i629t We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.13
The Apache Syncope team is pleased to announce the release of Syncope 2.1.13 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2113 Upgrading from 2.1.12? There are some notes about this process: https://s.apache.org/18gy2 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.0
The Apache Syncope team is pleased to announce the release of Syncope 3.0.0 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope300 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.0-M2
The Apache Syncope team is pleased to announce the release of Syncope 3.0.0-M2 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope300M2 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 3.0.0-M1
The Apache Syncope team is pleased to announce the release of Syncope 3.0.0-M1 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope300M1 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 3.0.0-M0
The Apache Syncope team is pleased to announce the release of Syncope 3.0.0-M0 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . Syncope 3.0 Maggiore is now a full-fledged IAM system covering provisioning, reconciliation and reporting needs (as with earlier releases), access management and API management. The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope300M0 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.12
The Apache Syncope team is pleased to announce the release of Syncope 2.1.12 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2112 Upgrading from 2.1.11? There are some notes about this process: https://s.apache.org/he0xc We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.11
The Apache Syncope team is pleased to announce the release of Syncope 2.1.11 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2111 Upgrading from 2.1.10? There are some notes about this process: https://s.apache.org/b9qvq We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache OpenJPA 3.2.2
The Apache OpenJPA team is pleased to announce the release of OpenJPA 3.2.2 Apache OpenJPA is a persistent object management kernel for databases, relational as well as non-relational. For relational databases, OpenJPA is compliant to the Java Persistence Architecture (JPA) version 2.2. OpenJPA runs in stand-alone Java SE as well as containers e.g Java EE, Tomcat, Spring or OSGi. The release will be available within 24h from Central Maven Repository and: https://openjpa.apache.org/downloads Read the full change log available here: https://openjpa.apache.org/builds/3.2.2/apache-openjpa/RELEASE-NOTES.html We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at https://openjpa.apache.org/ The Apache OpenJPA Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 2.1.10
The Apache Syncope team is pleased to announce the release of Syncope 2.1.10 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2110 Upgrading from 2.1.9? There are some notes about this process: https://s.apache.org/lc4y9 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 2.1.9
The Apache Syncope team is pleased to announce the release of Syncope 2.1.9 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope219 Upgrading from 2.1.8? There are some notes about this process: https://s.apache.org/4ofso We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.8
The Apache Syncope team is pleased to announce the release of Syncope 2.1.8 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope218 Upgrading from 2.1.7? There are some notes about this process: https://s.apache.org/s29ad We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.7
The Apache Syncope team is pleased to announce the release of Syncope 2.1.7 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope217 Upgrading from 2.1.6? There are some notes about this process: https://s.apache.org/4mip8 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.16
The Apache Syncope team is pleased to announce the release of Syncope 2.0.16 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2016 Upgrading from 2.0.15? There are some notes about this process: https://s.apache.org/60s6n We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[CVE-2020-11977] Apache Syncope: Remote Code Execution via Flowable workflow definition
Description: When the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution. Severity: Low Vendor: The Apache Software Foundation Affects: 2.1.X releases prior to 2.1.7 Solution: 2.1.X users: upgrade to 2.1.7 Credit: This issue was discovered by ch0wn of Orz Lab.
[CVE-2019-17557] Apache Syncope Enduser UI XSS
Description: It was found that the EndUser UI login page reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string. Severity: Medium Vendor: The Apache Software Foundation Affects: 2.0.X releases prior to 2.0.15 2.1.X releases prior to 2.1.6 Solution: 2.0.X users: upgrade to 2.0.15 2.1.X users: upgrade to 2.1.6 Credit: This issue was independently discovered by CNCERT songmingxuan and GitHub Security Lab team member Alvaro Muñoz - https://github.com/pwntester
[CVE-2020-1961] Apache Syncope Server-Side Template Injection on mail templates
Description: Vulnerability to Server-Side Template Injection on Mail templates enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered. Severity: Important Vendor: The Apache Software Foundation Affects: 2.0.X releases prior to 2.0.15 2.1.X releases prior to 2.1.6 Solution: 2.0.X users: upgrade to 2.0.15 2.1.X users: upgrade to 2.1.6 Credit: This issue was discovered by GitHub Security Labs team member Alvaro Muñoz - https://github.com/pwntester.
[ANN] Apache Syncope 2.1.6
The Apache Syncope team is pleased to announce the release of Syncope 2.1.6 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope216 Upgrading from 2.1.5? There are some notes about this process: https://s.apache.org/5esvf We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.15
The Apache Syncope team is pleased to announce the release of Syncope 2.0.15 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2015 Upgrading from 2.0.14? There are some notes about this process: https://s.apache.org/fra2f We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[CVE-2020-1959] Multiple Remote Code Execution Vulnerabilities
Description: A Server-Side Template Injection was identified in Syncope enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code. Severity: Important Vendor: The Apache Software Foundation Affects: 2.1.X releases prior to 2.1.6 Solution: Upgrade to 2.1.6 Credit: This issue was discovered by GitHub Security Labs team member Alvaro Muñoz - https//github.com/pwntester. References: https://syncope.apache.org/security
[ANN] Apache Syncope 2.0.14
The Apache Syncope team is pleased to announce the release of Syncope 2.0.14 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope2014 Upgrading from 2.0.13? There are some notes about this process: https://s.apache.org/kz33c We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.5
The Apache Syncope team is pleased to announce the release of Syncope 2.1.5 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: https://syncope.apache.org/downloads Read the full change log available here: https://s.apache.org/syncope215 Upgrading from 2.1.4? There are some notes about this process: https://s.apache.org/e08nr We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.4
The Apache Syncope team is pleased to announce the release of Syncope 2.1.4 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope214 Upgrading from 2.1.3? There are some notes about this process: https://s.apache.org/wvOo We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.13
The Apache Syncope team is pleased to announce the release of Syncope 2.0.13 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope2013 Upgrading from 2.0.12? There are some notes about this process: https://s.apache.org/8U9F We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.12
The Apache Syncope team is pleased to announce the release of Syncope 2.0.12. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope2012 Upgrading from 2.0.11? There are some notes about this process: https://s.apache.org/pCzv We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.3
The Apache Syncope team is pleased to announce the release of Syncope 2.1.3 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope213 Upgrading from 2.1.2? There are some notes about this process: https://s.apache.org/NPtt We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[SECURITY] CVE-2018-17184 Apache Syncope
CVE-2018-17184: Stored XSS Description: A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed. Severity: Important Vendor: The Apache Software Foundation Affects: Releases prior to 2.1.2 Releases prior to 2.0.11 Solution: 2.0.X users should upgrade to 2.0.11 2.1.X users should upgrade to 2.1.2 Credit: This issue was discovered by Kevin Borras Soler. References: https://syncope.apache.org/security signature.asc Description: OpenPGP digital signature
[SECURITY] CVE-2018-17186 Apache Syncope
CVE-2018-17186: XXE on BPMN definitions Description: An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution. Severity: Medium Vendor: The Apache Software Foundation Affects: Releases prior to 2.1.2 Releases prior to 2.0.11 The unsupported Releases 1.2.x may be also affected. Solution: 2.0.X users should upgrade to 2.0.11 2.1.X users should upgrade to 2.1.2 Mitigation: Do not assign workflow definition entitlements to any administrator. Credit: This issue was discovered by Kevin Borras Soler and Joan Bono. References: https://syncope.apache.org/security signature.asc Description: OpenPGP digital signature
[ANN] Apache Syncope 2.1.2
The Apache Syncope team is pleased to announce the release of Syncope 2.1.2. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope212 Upgrading from 2.1.1? There are some notes about this process: https://s.apache.org/fDIR We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.11
The Apache Syncope team is pleased to announce the release of Syncope 2.0.11. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope2011 Upgrading from 2.0.10? There are some notes about this process: https://s.apache.org/zVEH We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.10
The Apache Syncope team is pleased to announce the release of Syncope 2.0.10. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope2010 Upgrading from 2.0.9? There are some notes about this process: https://s.apache.org/XHzE We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.1
The Apache Syncope team is pleased to announce the release of Syncope 2.1.1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope211 Upgrading from 2.1.0? There are some notes about this process: https://s.apache.org/6OHG We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.1.0
The Apache Syncope team is pleased to announce the release of Syncope 2.1.0. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope210 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.9
The Apache Syncope team is pleased to announce the release of Syncope 2.0.9. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope209 Upgrading from 2.0.7? There are some notes about this process: https://s.apache.org/9m0G We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[SECURITY] CVE-2018-1321: Remote code execution by administrators with report and template entitlements
CVE-2018-1321: Remote code execution by administrators with report and template entitlements Severity: Medium Vendor: The Apache Software Foundation Versions Affected: * Releases prior to 1.2.11 * Releases prior to 2.0.8 The unsupported Releases 1.0.x, 1.1.x may be also affected. Description: An administrator with report and template entitlements can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution. Solution: Syncope 1.2.x users upgrade to 1.2.11. Syncope 2.0.x users upgrade to 2.0.8. Mitigation: Do not assign report and template entitlements to any administrator. Credit: This issue was discovered by Che-Chun Kuo. References: [1] http://syncope.apache.org/security.html
[SECURITY] CVE-2018-1322: Information disclosure via FIQL and ORDER BY sorting
CVE-2018-1322: Information disclosure via FIQL and ORDER BY sorting Severity: Medium Vendor: The Apache Software Foundation Versions Affected: * Releases prior to 1.2.11 * Releases prior to 2.0.8 The unsupported Releases 1.0.x, 1.1.x may be also affected. Description: An administrator with user search entitlements can recover sensitive security values using the fiql and orderby parameters. Solution: Syncope 1.2.x users upgrade to 1.2.11. Syncope 2.0.x users upgrade to 2.0.8. Mitigation: Do not assign user search entitlements to any administrator. Credit: This issue was discovered by Che-Chun Kuo. References: [1] http://syncope.apache.org/security.html
[ANN] Apache Syncope 1.2.11
The Apache Syncope team is pleased to announce the release of Syncope 1.2.11. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope1211 Upgrading from 1.2.10? There are some notes about this process: https://s.apache.org/g3gl We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.8
The Apache Syncope team is pleased to announce the release of Syncope 2.0.8. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope208 Upgrading from 2.0.7? There are some notes about this process: https://s.apache.org/m6MG We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.7
The Apache Syncope team is pleased to announce the release of Syncope 2.0.7. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope207 Upgrading from 2.0.6? There are some notes about this process: https://s.apache.org/pucD We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.6
The Apache Syncope team is pleased to announce the release of Syncope 2.0.6. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope206 Upgrading from 2.0.4? There are some notes about this process: https://s.apache.org/6urO We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.5
The Apache Syncope team is pleased to announce the release of Syncope 2.0.5. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log available here: https://s.apache.org/syncope205 Upgrading from 2.0.4? There are some notes about this process: https://s.apache.org/FeOB We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.4
The Apache Syncope team is pleased to announce the release of Syncope 2.0.4. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Read the full change log is available here: https://s.apache.org/syncope204 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.3
The Apache Syncope team is pleased to announce the release of Syncope 2.0.3. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html Despite being a minor release, and besides the high number of fixes provided, this new release brings several new features and improvements. Read the full change log is available here: https://s.apache.org/syncope203 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.2 released
The Apache Syncope team is pleased to announce the release of Syncope 2.0.2. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope202 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.10 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.10. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope1210 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache OpenJPA 2.4.2 released
The Apache OpenJPA team is pleased to announce the release of OpenJPA 2.4.2. Apache OpenJPA is a Java persistence project at The Apache Software Foundation that can be used as a stand-alone POJO persistence layer or integrated into any Java EE compliant container and many other lightweight frameworks, such as Tomcat and Spring. The 1.x releases are a production ready, feature-rich, compliant implementation of the Java Persistence API (JPA) 1.0 part of the JSR-220 Enterprise Java Beans 3.0 specification, which pass the Sun JPA 1.0b Technology Compatibility Kit. The 2.x releases are a production ready, compliant implement of the JSR-317 Java Persistence 2.0 specification, which is backwards compatible to the JPA 1.0 specification and passes the Sun JPA 2.0 Technology Compatibility Kit. The release will be available within 24h from: http://openjpa.apache.org/downloads.html The full change log is available here: http://openjpa.apache.org/openjpa-2.4.x.html We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://openjpa.apache.org/ The Apache OpenJPA Team
[ANN] Apache Syncope 2.0.1 released
The Apache Syncope team is pleased to announce the release of Syncope 2.0.1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope201 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.9 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.9. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope129 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 2.0.0.M5 released
The Apache Syncope team is pleased to announce the release of Syncope 2.0.0.M5. This is the last milestone before the final 2.0.0 release. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology. The releases will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope200M5 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Involved at The Apache Software Foundation: member, Syncope PMC chair, Cocoon PMC, Olingo PMC, CXF Committer, OpenJPA Committer, PonyMail PPMC http://home.apache.org/~ilgrosso/
[ANN] Apache Syncope 2.0.0-M4 released
The Apache Syncope team is pleased to announce the release of Syncope 2.0.0-M4. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology. The releases will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope200M4 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.8 and 2.0.0-M2 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.8 and 2.0.0-M2. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The releases will be available within 24h from: http://syncope.apache.org/downloads.html The full change logs are available here: https://s.apache.org/syncope128 https://s.apache.org/syncope200M3 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 2.0.0-M2 released
The Apache Syncope team is pleased to announce the release of Syncope 2.0.0-M2. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: https://s.apache.org/syncope200M2 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.7 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.7. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope127 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Involved at The Apache Software Foundation: member, Syncope PMC chair, Cocoon PMC, Olingo PMC, CXF committer http://people.apache.org/~ilgrosso/
[ANN] Apache Syncope 2.0.0-M1 released
The Apache Syncope team is pleased to announce the release of Syncope 2.0.0-M1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope200M1 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.2 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.2. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope122 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.1 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope121 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.0 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.0. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope120 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.2.0-M1 released
The Apache Syncope team is pleased to announce the release of Syncope 1.2.0-M1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope120M1 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[SECURITY] CVE-2014-3503 Apache Syncope
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-3503: Insecure Random implementations used to generate passwords in Apache Syncope Severity: Major Vendor: The Apache Software Foundation Versions Affected: This vulnerability affects all versions of Apache Syncope 1.1.x prior to 1.1.8 'Ad libitum'. The 1.0.x releases are not affected. Description: A password is generated for a user in Apache Syncope under certain circumstances, when no existing password is found. However, the password generation code is relying on insecure Random implementations, which means that an attacker could attempt to guess a generated password. This has been fixed in revision: http://svn.apache.org/viewvc?view=revision&revision=1596537 Migration: Syncope 1.0.x users are not affected by this issue. Syncope 1.1.x users should upgrade to 1.1.8 'Ad libitum' as soon as possible. References: http://syncope.apache.org/security.html -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGBQJTunsUAAoJEGe/gLEK1TmDj4AH/05J9ZOB/gyem18F9MTcG+PB tuX7EGemHCU+fyKeTetyGdhzZzdNquMA3mR4UXOEKH1Fok4LvkBWF+BoKMSY8DgY vtWcZUfdJFeUd1XpdUrW0D/GEbbIdmijkbVoAZ3703RMpRiDBiVBkaBr/tjC6tuf WUoBueRmNTkInBQhabaNYXvC0vyPA5ARhu1CprJ5QpA3aFoIEaVdlJTd+Mg58vJS tlwoyGIUEUY/pusBKaZDkTVAJhrOS9b5atjlqCPlT3kGUbQOYgRPPTihX+0CMIY2 JE4yUXR8Kx6tvgebtft2IoUp6oZdR+XqHnEe3Tv1UnSRmlHj6o+tTCBDMmm1YOY= =o17e -END PGP SIGNATURE-
[ANN] Apache Syncope 1.1.8 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.8. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/syncope118 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.0.9 and 1.1.7 released
The Apache Syncope team is pleased to announce the release of Syncope 1.0.9 and 1.1.7. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The releases will be available within 24h from: http://syncope.apache.org/downloads.html The full change logs are available here: http://s.apache.org/syncope117 http://s.apache.org/syncope109 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[SECURITY] CVE-2014-0111 Apache Syncope
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-0111: Remote code execution by an authenticated administrator Severity: Important Vendor: The Apache Software Foundation Versions Affected: Syncope 1.0.0 to 1.0.8 Syncope 1.1.0 to 1.1.6 Description: In the various places in which Apache Commons JEXL expressions are allowed (derived schema definition, user / role templates, account links of resource mappings) a malicious administrator can inject Java code that can be executed remotely by the JEE container running the Apache Syncope core. Credit: This issue was discovered by Grégory Draperi. References: http://syncope.apache.org/security.html -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.14 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQEcBAEBAgAGBQJTTOJyAAoJEGtDE+0nPfKHxWcIAI9POTzr4bIF7fXO25uXgfny BO8SR0fmGScdmeohf8nQZbUNgKA1F7YRe5vC9r8nKFSpdDJrMnPSTOwMYrgdOxHt Rl/SpEab4b8NX0FO1a6TObDbXBDj+Q+4cNUXOOc0jC7lU67n1SorfGaMbjLfcZ0w 2xnZsbAQ0P0bmIJ2mR+LuXLsEA3kwvClF9fUTEDlJ4Rm/yT16UGvD5+vEJdMQzen JhBdT8VeX4wvtYr9+WmmWqeWgvSmezE07s5Pu36qXkxAEFGzdQBtJ/XJbpbgM7Sa 7MoZQHQqJ5VwUVGMseqcxhAjD065uHP41HpAeF4TFQvp4jg8/FiybFdXqiJ+smI= =4XQi -END PGP SIGNATURE-
[ANN] Apache Syncope 1.1.6 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.6. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://ur1.ca/gpa27 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.1.4 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.4. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/PKg We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.1.3 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.3. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/2L4 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.1.1 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/cp0 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.1.1 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: ttp://s.apache.org/cp0 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.0.8 released
The Apache Syncope team is pleased to announce the release of Syncope 1.0.8. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/QTR We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.1.0 released
The Apache Syncope team is pleased to announce the release of Syncope 1.1.0. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/P8C We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.0.7 released
The Apache Syncope team is pleased to announce the release of Syncope 1.0.7. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/3cx We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.0.6 released
The Apache Syncope team is pleased to announce the release of Syncope 1.0.7. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/3cx We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Cocoon Integration Test Framework 1.0.1 and Servlet Service Implementation 1.3.2
The Apache Cocoon team is pleased to announce the release of subprojects Cocoon Integration Test Framework 1.0.1 and Servlet Service Implementation 1.3.2. Apache Cocoon is an XML processing framework built around the concepts of separation of concerns and component-based development. Apache Cocoon 3 is a major rewrite of Cocoon 2.2. Like Cocoon 2 it is based around the concept of pipelines and sitemaps and it is very similar to Cocoon 2.2 in many respects but is slimmed down and designed to be easily used with Java code (= no frameworks required!). On top of this, Cocoon 3 has the goal of becoming the best available platform for RESTful web services and web applications. Subprojects are libraries, shared by different Apache Cocoon versions, that can be used independently from the rest of Cocoon (1.x, 2.x 3.x), or any of its parts (such as sitemap, pipelines, blocks, etc.). Take a look at subprojects site http://cocoon.apache.org/subprojects/ and Maven plugins site http://cocoon.apache.org/2.2/maven-plugins/ for more details. We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://cocoon.apache.org/ The Apache Cocoon Team
[ANN] Apache Syncope 1.0.4
The Apache Syncope team is pleased to announce the release of Syncope 1.0.4 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.html The full change log is available here: http://s.apache.org/Qbw We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://syncope.apache.org/ The Apache Syncope Team
[ANN] Apache Syncope 1.0.2-incubating released
The Apache Syncope team is pleased to announce the release of Syncope 1.0.2-incubating from the Apache Incubator. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://incubator.apache.org/syncope/downloads.html The full change log is available here: http://s.apache.org/Ikt We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://incubator.apache.org/syncope/ The Apache Syncope Team
[ANN] Apache Syncope 1.0.0-incubating released
After 7 months of work the Apache Syncope team is proud to announce the final release of the first stable version since entering the Apache Incubator. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release will be available within 24h from: http://incubator.apache.org/syncope/downloads.html The full change log is available here: http://s.apache.org/cid We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://incubator.apache.org/syncope/ The Apache Syncope Team
Apache Cocoon Subprojects New Releases
During the last weeks the Apache Cocoon Community released a new version of each one of 11 subprojects currently managed. Subprojects are libraries, shared by different Apache Cocoon versions, that can be used independently from the rest of Cocoon (1.x, 2.x 3.x), or any of its parts (such as sitemap, pipelines, blocks, etc.). Here it follows the detailed list of new releases: Block-Deployment 1.2.1 Configuration API 1.0.4 Spring Configurator 2.2.1 JNet 1.2.2 Servlet-Service Framework 1.3.1 Maven Plugin 1.0.2 RCL Spring Reloader and WebApp Wrapper 1.0.2 Integration Test Framework 1.0.0 XML Utilities 2.0.4 Serializers Charsets 1.0.2 Take a look at subprojects site http://cocoon.apache.org/subprojects/ and Maven plugin site http://cocoon.apache.org/2.2/maven-plugins/ for more details. The Apache Cocoon Team. -- Francesco Chicchiriccò ASF Member, Apache Cocoon PMC and Apache Syncope PPMC Member http://people.apache.org/~ilgrosso/
[ANN] Apache Syncope 1.0.0-RC1-incubating released
The Apache Syncope team is pleased to announce the release of Syncope 1.0.0-RC1-incubating from the Apache Incubator. This is the first release of Apache Syncope,an Open Source system for managing digital identities in enterprise environments, implemented in JEE technology . The release is available here: http://incubator.apache.org/syncope/downloads.html The full change log is available here: https://cwiki.apache.org/confluence/display/SYNCOPE/Espressivo#Espressivo-1.0.0RC1incubating%28June1st%2C2012%29 We welcome your help and feedback. For more information on how to report problems, and to get involved, visit the project website at http://incubator.apache.org/syncope/ The Apache Syncope Team