[ANNOUNCE] Apache Qpid Proton 0.35.0 released

2021-07-02 Thread Robbie Gemmell
The Apache Qpid (https://qpid.apache.org) community is pleased to announce the immediate availability of Apache Qpid Proton 0.35.0. Apache Qpid Proton is a messaging library for the Advanced Message Queuing Protocol 1.0 (AMQP 1.0, ISO/IEC 19464, https://www.amqp.org). It can be used in a wide

The Apache News Round-up: week ending 2 July 2021

2021-07-02 Thread Sally Khudairi
[this newsletter is available online at https://s.apache.org/wynzf ] Hello, July --we're midway through the year already. It's been another great week; let's see what the Apache community has been up to: Apache Month in Review – a round-up of our Round-ups and other newsworthy bits over the

CVE-2021-26920: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended

2021-07-02 Thread Jihoon Son
Severity: low Description: In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the