[ANNOUNCE] Apache Groovy 3.0.20 Released

2023-12-22 Thread Paul King
Dear community, The Apache Groovy team is pleased to announce version 3.0.20 of Apache Groovy. Apache Groovy is a multi-faceted programming language for the JVM. Further details can be found at the https://groovy.apache.org website. This release is a maintenance release of the GROOVY_3_0_X branch

[ANNOUNCE] Release Apache Groovy 5.0.0-alpha-4

2023-12-22 Thread Paul King
Dear community, The Apache Groovy team is pleased to announce version 5.0.0-alpha-4 of Apache Groovy. Apache Groovy is a multi-faceted programming language for the JVM. Further details can be found at the https://groovy.apache.org website. This is a pre-release of a new version of Groovy. We grea

[ANNOUNCE] Release Apache InLong 1.10.0

2023-12-22 Thread Verne Deng
Hi all, The Apache InLong community is pleased to announce that Apache InLong 1.10.0 has been released! Apache InLong is a one-stop integration framework for massive data that provides automatic, secure, distributed, and efficient data publishing and subscription capabilities. This platform helps

[ANNOUNCE] Apache Groovy 4.0.17 Released

2023-12-22 Thread Paul King
Dear community, The Apache Groovy team is pleased to announce version 4.0.17 of Apache Groovy. Apache Groovy is a multi-faceted programming language for the JVM. Further details can be found at the https://groovy.apache.org website. This release is a maintenance release of the GROOVY_4_0_X branch

[ANNOUNCE] Apache OFBiz 18.12.11 released

2023-12-22 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.11". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.11" is the elev

CVE-2023-51656: Apache IoTDB: Unsafe deserialize map in Sync Tool

2023-12-22 Thread Haonan Hou
Severity: low Affected versions: - Apache IoTDB 0.13.0 through 0.13.4 Description: Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue. References

[ANNOUNCE] Apache Arrow 14.0.2 released

2023-12-22 Thread Raúl Cumplido
The Apache Arrow community is pleased to announce the 14.0.2 release. It includes 33 resolved issues ([1]) since the 14.0.1 release. The release is available now from our website and [2]: http://arrow.apache.org/install/ Read about what's new in the release https://arrow.apache.org/blog/2023/

[ANNOUNCE] Apache Pulsar Helm Chart version 3.1.0 Released

2023-12-22 Thread Lari Hotari
The Apache Pulsar team is pleased to announce the release of the Apache Pulsar Helm Chart 3.1.0. The official source release, as well as the binary Helm Chart release, are available at https://downloads.apache.org/pulsar/helm-chart/3.1.0/. The helm chart index at https://pulsar.apache.org/charts/

CVE-2023-49920: Apache Airflow: Missing CSRF protection on DAG/trigger

2023-12-22 Thread Ephraim Anierobi
Severity: moderate Affected versions: - Apache Airflow 2.7.0 before 2.8.0 Description: Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opene

CVE-2023-48291: Apache Airflow: Improper access control to DAG resources

2023-12-22 Thread Ephraim Anierobi
Severity: moderate Affected versions: - Apache Airflow before 2.8.0 Description: Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to variou

CVE-2023-50783: Apache Airflow: Improper access control vulnerability on the "varimport" endpoint

2023-12-22 Thread Ephraim Anierobi
Severity: low Affected versions: - Apache Airflow before 2.8.0 Description: Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable manag

CVE-2023-47265: Apache Airflow: DAG Params alllow to embed unchecked Javascript

2023-12-22 Thread Ephraim Anierobi
Severity: low Affected versions: - Apache Airflow 2.6.0 before 2.8.0 Description: Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascrip