[ANNOUNCE] Apache Jackrabbit Oak 1.16.0 released

2019-07-29 Thread Julian Reschke
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit Oak 1.16.0. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit Oa

[ANNOUNCE] Apache Rya 4.0.0-incubating released

2019-07-29 Thread Aaron D. Mihalik
The Apache Rya (Incubating) team is happy to announce the release of Apache Rya 4.0.0-incubating: https://rya.incubator.apache.org/news/2019/07/27/release-4.0.0/ Rya (pronounced "ree-uh" /rēə/) is a cloud-based RDF triple store that supports SPARQL queries. Rya is a scalable RDF data management s

[CVE-2018-11772] Apache VCL SQL injection attack in privilege management

2019-07-29 Thread Josh Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2018-11772: Apache VCL SQL injection attack in privilege management Severity: Medium Versions Affected: 2.1 through 2.5 Description: Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if a

[CVE-2018-11773] Apache VCL improper form validation in block allocation management

2019-07-29 Thread Josh Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2018-11773: Apache VCL improper form validation in block allocation management Severity: Medium Versions Affected: 2.1 through 2.5 Description: Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitt

[CVE-2018-11774] Apache VCL SQL injection attack in VM management

2019-07-29 Thread Josh Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2018-11774: Apache VCL SQL injection attack in VM management Severity: Medium Versions Affected: 2.1 through 2.5 Description: Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from

[ANNOUNCE] release of Apache VCL 2.5.1

2019-07-29 Thread Josh Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The Apache VCL project is pleased to announce the release of version 2.5.1. This is primarily a bug fix release. However, there are a few items worth highlighting: * PHP code updated to work with PHP 7.x. * Rudimentary NFS file share mounting exten

[ANNOUCEMENT] Apache Commons Pool 2.7.0

2019-07-29 Thread Gary Gregory
The Apache Commons Pool team is pleased to announce the release of Apache Commons Pool 2.7.0. Apache Commons Pool provides an object-pooling API and a number of object pool implementations. Version 2 contains a completely re-written pooling implementation compared to the 1.x series. In addition to