[ANN] Apache Cocoon 2.1 and 3.0 retired

2024-01-12 Thread Cédric Damioli
Apache Cocoon 2.1 and 3.0 retired -   After the recent release of Cocoon 2.3.0, the Apache Cocoon Community has   decided to retire both 2.1 and 3.0 versions, to focus on further developments   of the 2.3 branch   The 2.1 branch was first released mo

CVE-2022-45135: Apache Cocoon: SQL injection in DatabaseCookieAuthenticatorAction

2023-11-30 Thread Cédric Damioli
Severity: moderate Affected versions: - Apache Cocoon 2.2.0 before 2.3.0 Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrad

CVE-2023-49733: Apache Cocoon's StreamGenerator is vulnerable to XXE injection

2023-11-30 Thread Cédric Damioli
Severity: important Affected versions: - Apache Cocoon 2.2.0 before 2.3.0 Description: Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes

[ANN] Apache Cocoon 2.3.0 Released

2023-11-28 Thread Cédric Damioli
Apache Cocoon 2.3.0 Released -   The Apache Cocoon Community is proud to announce the release of   Cocoon 2.3.0.   Apache Cocoon is a Spring-based framework (since version 2.2 of   Cocoon) built around the concepts of separation of concerns and   component-based devel

[CVE-2020-11991] Apache Cocoon security vulnerability

2020-09-11 Thread Cédric Damioli
tent of /etc/shadow Credit: This issue was discovered by Nassim Asrir. Regards, -- Cédric Damioli

[ANN] Apache Cocoon 2.1.13 Released

2020-07-31 Thread Cédric Damioli
Apache Cocoon 2.1.13 Released -    The Apache Cocoon Community is proud to announce the new release    of Apache Cocoon.   Apache Cocoon is a web development framework built around the concept   of separation of concerns (that is: allowing people to do their job   w

[ANN] Apache Cocoon 2.1.12 Released

2013-03-20 Thread Cédric Damioli
The Apache Cocoon Project -- Cédric Damioli For more information about Apache Cocoon 2.1.12, please go to http://cocoon.apache.org Changes with Apache Cocoon 2.1.12 *) Starting with 2.1.12 the minimum required Java version will be 1.4.2. [all] *) Core: Update xml-commons-resolver to 1.