CVE-2022-23206: Apache Traffic Control: Server-Side Request Forgery in Traffic Ops endpoint POST /user/login/oauth

2022-02-04 Thread Zach Hoffman
Description: In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. Mitigation: 6.0.x user should upgrade to

[ANNOUNCE] Release Apache Traffic Control 6.1.0

2022-02-04 Thread Zach Hoffman
The Apache Traffic Control team is proud to announce the release of Apache Traffic Control 6.1.0, which contains various new features and bug fixes. Apache Traffic Control allows you to build a large scale content delivery network using open source. Built around Apache Traffic Server as the cachin

The Apache News Round-up: week ending 4 February 2022

2022-02-04 Thread Swapnil M Mane
Welcome, February --we're opening the month with another great week. Here's what the Apache community has been up to: ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws. - Next Board Meeting: 16 February 2022. Board calendar

[ANNOUNCE] Apache Hudi 0.10.1 released

2022-02-04 Thread Sivabalan
The Apache Hudi team is pleased to announce the release of Apache Hudi 0.10.1. Apache Hudi (pronounced Hoodie) stands for Hadoop Upserts Deletes and Incrementals. Apache Hudi manages storage of large analytical datasets on DFS (Cloud stores, HDFS or any Hadoop FileSystem compatible storage) an

[ANNOUNCE] Apache Camel 3.15.0 Released

2022-02-04 Thread Gregor Zurowski
The Camel PMC is pleased to announce the release of Apache Camel 3.15.0. Apache Camel is an open source integration framework that empowers you to quickly and easily integrate various systems consuming or producing data. This release is a new minor release and contains 217 bug fixes and improveme

[ANNOUNCE] Apache Jackrabbit Oak 1.8.26 released

2022-02-04 Thread Nitin Gupta
The Apache Jackrabbit community is pleased to announce the release of Apache Jackrabbit Oak 1.8.26. The release is available for download at: http://jackrabbit.apache.org/downloads.html See the full release notes below for details about this release: Release Notes -- Apache Jackrabbit