[ANNOUNCE] Apache Airflow 2.2.4 Released

2022-02-25 Thread Jedidiah Cunningham
Dear community, I'm happy to announce that Airflow 2.2.4 was just released. The released sources and packages can be downloaded via https://airflow.apache.org/docs/apache-airflow/stable/installation/installing-from-sources.html Other installation methods are described in

[ANNOUNCE] Apache JSPWiki 2.11.2 released

2022-02-25 Thread Juan Pablo Santos Rodríguez
The Apache JSPWiki team is pleased to announce the release of JSPWiki 2.11.2. This is the third release on the 2.11 series of Apache JSPWiki, a feature-rich and extensible WikiWiki engine built around the standard JEE components. The release is available here:

CVE-2021-45229: Apache Airflow: Reflected XSS via Origin Query Argument in URL

2022-02-25 Thread Jedidiah Cunningham
Severity: high Description: It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below. Credit: The Apache Airflow PMC would like to thank both Bogdan Kurinnoy of the

The Apache Weekly News Round-up: week ending 25 February 2022

2022-02-25 Thread Swapnil M Mane
Farewell, February --we're wrapping up the month with another great week. Here are the latest updates on the Apache community's activities: ASF Board – management and oversight of the business affairs of the corporation in accordance with the Foundation's bylaws. - Next Board Meeting: 16 March