Re: CVE-2022-26650: Apache ShenYu (incubating) Regular expression denial of service

2022-05-18 Thread Zhang Yonglun
Add credit. Severity: moderate Description: In ShenYu-Bootstrap there's RegexPredicateJudge.java which uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular express

[ANNOUNCE] Apache Ignite Extensions Released

2022-05-18 Thread Maxim Muzafarov
The Apache Ignite Community is pleased to announce the release of the following Apache Ignite Extensions: - Ignite AWS Extension 1.0.0 - Ignite Azure Extension 1.0.0 - Ignite GCE Extension 1.0.0 - Ignite Spring Data Extension 2.0.0 - Ignite Spring Session Extension 1.0.0 - Ignite Zookeeper Ip Finde

[ANNOUNCE] Apache Kafka 3.2.0

2022-05-18 Thread Bruno Cadonna
The Apache Kafka community is pleased to announce the release for Apache Kafka 3.2.0 * log4j 1.x is replaced with reload4j (KAFKA-9366) * StandardAuthorizer for KRaft (KIP-801) * Send a hint to the partition leader to recover the partition (KIP-704) * Top-level error code field in DescribeLogDir