Re: iCalendar integration not working

2018-10-05 Thread jler...@apache.org
Hi Jyri, Thanks for your detailed report, it's fixed with https://issues.apache.org/jira/browse/OFBIZ-10595 So you need to apply a patch if you want to use the last R16 release HTH Jacques Le 03/10/2018 à 15:26, Jyri Sillanpaa a écrit : Hi Jacques, Right click on Thunderbird Calendar tab

Re: OFbiz on LAMP server

2018-10-07 Thread jler...@apache.org
Yes, it's that. It's a bit dated but should still be OK. What are your problems exactly? Jacques Le 07/10/2018 à 18:58, Wolfgang Paul Rauchholz a écrit : Do you refer to this link? https://cwiki.apache.org/confluence/display/OFBIZ/FAQ+-+Tips+-+Tricks+-+Cookbook+-+HowTo#FAQ-Tips-Tricks-Cookboo

Re: Missing State/Province

2018-10-08 Thread jler...@apache.org
Hi Wolfgang, Please see my answer in the Jira, better to exchange there now Jacques Le 08/10/2018 à 09:04, Wolfgang Paul Rauchholz a écrit : I am happy to help. But, being a non-technical person, I need explanations in layman terms. 'CommonWorker.getAssociatedStateList' does not tell me anyth

[CVE-2019-0235 ] Apache OFBiz multiple CSRF vulnerabilities

2020-04-30 Thread jler...@apache.org
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 17.12.01 Description: Apache OFBiz is vulnerable to CSRF attacks Mitigation: Upgrade to 17.12.03 or manually apply the commits at OFBIZ-11470 Credit: Initially known by the OFBiz security team (OFBIZ-1042

Re: Demos shutdown because possible security issues

2020-12-07 Thread jler...@apache.org
Le 07/12/2020 à 10:02, Jacques Le Roux a écrit : Try removing the file, it should pass Mmm no, in this case the qrcode is not rendered. We can improve that but not in your package. Could you please create a Jira? Jacques

Re: Help needed for Ofbiz version 17.12 Update operation

2020-12-17 Thread jler...@apache.org
Hi Avijit, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the

Re: buildbot exception in on ofbizTrunkFramework

2020-12-18 Thread jler...@apache.org
Fixed, the trunk demo is accessible again Sorry for the quirk Le 18/12/2020 à 16:18, Jacques Le Roux a écrit : OK, it's a Shiro version issue, checking that Exception in thread "main" org.apache.shiro.crypto.CryptoException: Unable to execute 'doFinal' with cipher instance [javax.crypto.Ciphe

Re: Videos on Apache mailing lists and how to subscribe/unsubscribe

2020-12-29 Thread jler...@apache.org
+1 Thanks Swapnil! Le 29/12/2020 à 06:35, Suraj Khurana a écrit : Thanks Swapnil for sharing these videos. -- Best Regards, Suraj Khurana Senior Technical Consultant On Mon, Dec 28, 2020 at 8:19 PM Swapnil M Mane wrote: Dear all, Hope you are doing well. As we got various queries on how

Subject: [CVE-2021-26295] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

2021-03-21 Thread jler...@apache.org
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 17.12.06 Description: Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz. Mitigation: Upgrade

[CVE-2021-29200] RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

2021-04-27 Thread jler...@apache.org
Severity: High, possible RCE Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 17.12.07 Description: Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform a RCE attack Mitigation: Upgrade to at least 17.12.07 or ap

[CVE-2021-30128] Unsafe deserialization in OFBiz

2021-04-27 Thread jler...@apache.org
Severity: High, possible RCE Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 17.12.07 Description: Apache OFBiz has unsafe deserialization prior to 17.12.07 version Mitigation: Upgrade to at least 17.12.07 or apply patches at https://issues.apache.org/jira/bro

[CVE-2021-37608] Arbitrary file upload vulnerability in OFBiz

2021-08-11 Thread jler...@apache.org
Severity: High, possible RCE Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 17.12.08 Description: Apache OFBiz has unsafe deserialization prior to 17.12.08 version Mitigation: Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/bro

Re: ApacheBookStore.com

2014-10-12 Thread jler...@apache.org
And if not, at least show OFBiz books, if the ApacheBookStore gets updated We have some in the learning section at https://cwiki.apache.org/confluence/display/OFBADMIN/OFBiz+Related+Books#OFBizRelatedBooks-Learning As mentioned there, those sold by /Packt pay a percentage of the sales back to th

Re: Comment: Apache OFBiz new blog

2015-07-07 Thread jler...@apache.org
Hi Amit, Please don't use the blog to ask your questions in comments but rather use the user ML see http://ofbiz.apache.org/mailing-lists.html Thanks Jacques Le 07/07/2015 12:32, priv...@ofbiz.apache.org a écrit : This comment failed validation for these reasons: Comment has more than 1000

CVE-2016-2170: Apache OFBiz information disclosure vulnerability

2016-04-08 Thread jler...@apache.org
== CVE-2016-2170: Apache OFBiz information disclosure vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 13.07.02 and 13.07.01 Apache OFBiz 12.04.05 and earlier releases in the series (12.04.*) The uns

Re: PRODUCTS AND CATEGORY MANAGEMENT--OFBIZ ECOMMERCE

2016-06-11 Thread jler...@apache.org
Hi Erick, Please help yourself https://cwiki.apache.org/confluence/display/OFBENDUSER/Apache+OFBiz+Business+Setup+Guide Please use rather user ML for such questions, see why here http://ofbiz.apache.org/mailing-lists.html You will get a better support and it's more fair to share with everybody

[ANNOUNCE] Apache OFBiz 17.12 End-Of-Life (EOL) announcement

2022-01-15 Thread jler...@apache.org
The Apache OFBiz Project Team would like to inform you that OFBiz 17.12.09 is the last release of the 17.12 branch, which has reached its end of life and won’t be longer officially supported. https://ofbiz.apache.org/release-notes-17.12.09.html This announcement takes place on 2022-01-15 and sta

[ANNOUNCE] Apache OFBiz 17.12 End-Of-Life (EOL) announcement

2022-01-21 Thread jler...@apache.org
The Apache OFBiz Project Team would like to inform you that OFBiz 17.12.09 is the last release of the 17.12 branch, which has reached its end of life and won't be longer officially supported. https://ofbiz.apache.org/release-notes-17.12.09.html This announcement takes place on 2022-01-21 and sta