Episode 64
Java / Misc
Google
Hardware x-over
Apache
- Richard moved to Maven 3.0.4 and is having no problems
- Apache Jackrabbit 2.4.0, 2.2.11 released http://jackrabbit.apache.org - lots of new features, fixes and improvements
- (not Java, but) Apache libcloud gone 0.8.0 http://libcloud.apache.org/
- Apache MyFaces CVE-2011-4367
Apache MyFaces information disclosure vulnerability
- affects MyFaces 2.0.1 - 2.0.11, 2.1.0 - 2.1.5
- MyFaces JavaServer Faces (JSF) allows relative paths in the
- javax.faces.resource 'ln' parameter or writing the url so the resource
- name include '..' sequences . An attacker could use the security
- vulnerability to view files that they should not be able to.
- http://<hostname>:<port>/<context-root>/faces/javax.faces.resource/../WEB-INF/web.xml
- MyFaces Core 2.0.12 and 2.1.6 released
- Apache Directory Studio 2.0M2
- Apache Directory DS 2.0.0-M5
- Apache LDAP API 1.0.0-M10
- HttpClient 4.1.3 GA
- Apache Hive 0.8.1 - distributed data warehouse on top of Hadoop
- Commons Configuration 1.8
- Commons Validator 1.4
- Lucy 0.3 (incubating)
Apache Lucy is full-text search engine library written in C and targeted at dynamic languages