n/a: CVE-2023-28158: Apache Archiva privilege escalation

2023-03-29 Thread Olivier Lamy
Description: Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. This issue is being tracked as

[ANNOUNCEMENT] Apache Commons Configuration 2.9.0

2023-03-29 Thread Gary Gregory
The Apache Commons team is pleased to announce Apache Commons Configuration 2.9.0. Commons Configuration assists in the reading of configuration/preferences files in various formats. Historical list of changes: https://commons.apache.org/proper/commons-configuration/changes-report.html For compl

[ANNOUNCE] Apache Camel 3.20.3 (LTS) Released

2023-03-29 Thread Gregor Zurowski
The Camel PMC is pleased to announce the release of Apache Camel 3.20.3 (LTS). Apache Camel is an open source integration framework that empowers you to quickly and easily integrate various systems consuming or producing data. This release is a new patch release with 44 fixes and improvements. I