[CVE-2019-0202] Apache Storm Logviewer file system access vulnerability

2019-07-24 Thread Stig Rohde Døssing
[CVEID]:CVE-2019-0202[PRODUCT]:Apache Storm[VERSION]:Apache Storm 0.9.1-incubating to 1.2.2[PROBLEMTYPE]:CWE-200: Information Exposure[DESCRIPTION]:The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm vers

[CVE-2018-1320] Apache Storm vulnerable Thrift version

2019-07-24 Thread Stig Rohde Døssing
[CVEID]:CVE-2018-1320[PRODUCT]:Apache Storm[VERSION]:Apache Storm 0.9.1-incubating to 1.2.2[PROBLEMTYPE]:CWE-20: Input Validation[DESCRIPTION]:Apache Storm versions 0.9.1-incubating to 1.2.2 use Thrift library versions vulnerable to CVE-2018-1320. Mitigation: Upgrade to Apache Storm

[CVE-2018-11779] Apache Storm UI Java deserialization vulnerability

2019-07-24 Thread Stig Rohde Døssing
[CVEID]:CVE-2018-11779[PRODUCT]:Apache Storm[VERSION]:Apache Storm 1.1.0 to 1.2.2[PROBLEMTYPE]:CWE-502: Deserialization of Untrusted Data[DESCRIPTION]:In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is pos

[ANNOUNCEMENT] Apache Apache Commons Codec 1.13

2019-07-24 Thread Gary Gregory
The Apache Commons project is proud to announce Apache Apache Commons Codec 1.13. The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a co

[ANNOUNCE] Apache Subversion 1.9.12 released

2019-07-24 Thread Julian Foad
I'm happy to announce the release of Apache Subversion 1.9.12. Please choose the mirror closest to you by visiting: https://subversion.apache.org/download.cgi#supported-releases This is a stable bugfix release of the Apache Subversion open source version control system. SHA-512 checksums ar

[ANNOUNCE] Apache Subversion 1.10.6 released

2019-07-24 Thread Julian Foad
I'm happy to announce the release of Apache Subversion 1.10.6. Please choose the mirror closest to you by visiting: https://subversion.apache.org/download.cgi#supported-releases This is a stable bugfix release of the Apache Subversion open source version control system. SHA-512 checksums ar

[ANNOUNCE] Apache Subversion 1.12.2 released

2019-07-24 Thread Julian Foad
I'm happy to announce the release of Apache Subversion 1.12.2. Please choose the mirror closest to you by visiting: https://subversion.apache.org/download.cgi#recommended-release This is a stable bugfix release of the Apache Subversion open source version control system. SHA-512 checksums ar