Re: [CVE-2020-1953] Uncontrolled class instantiation when loading YAML files in Apache Commons Configuration

2020-03-12 Thread Oliver Heger
The form at Mitre was just submitted, so I assume that the issue will be visible soon. Oliver Am 12.03.20 um 19:18 schrieb Gary Gregory: > Note that https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-1953 is not > "live" yet. > > Gary > > On Thu, Mar 12, 2020 at 1:53 PM Oliver Heger wrote: >

Re: [CVE-2020-1953] Uncontrolled class instantiation when loading YAML files in Apache Commons Configuration

2020-03-12 Thread Gary Gregory
Note that https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-1953 is not "live" yet. Gary On Thu, Mar 12, 2020 at 1:53 PM Oliver Heger wrote: > CVE-2020-1953: Uncontrolled class instantiation when loading YAML files > in Apache Commons Configuration > > Severity: Moderate > > Vendor: > The Ap

[CVE-2020-1953] Uncontrolled class instantiation when loading YAML files in Apache Commons Configuration

2020-03-12 Thread Oliver Heger
CVE-2020-1953: Uncontrolled class instantiation when loading YAML files in Apache Commons Configuration Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: 2.2 to 2.6 Description: Apache Commons Configuration uses a third-party library to parse YAML files which by defau

Re: [geometry] JIRA project permissions

2020-03-12 Thread Matt Juntunen
Follow-up: I personally have admin privileges thanks to Alex[1]. There still seems to be an underlying issue but we may have all of the privileges we need for now. -Matt [1] https://issues.apache.org/jira/browse/INFRA-19956 From: Matt Juntunen Sent: Thursday, M

[ALL] Draft board report

2020-03-12 Thread Gary Gregory
I plan on submitting this report today. ## Description: The mission of Apache Commons is the creation and maintenance of Java focused reusable libraries and components ## Issues: There are no issues requiring board attention. ## Membership Data: Apache Commons was founded 2007-06-19 (13 years ag

[geometry] JIRA project permissions

2020-03-12 Thread Matt Juntunen
Hi Gary, The commons-geometry JIRA project may be misconfigured since it seems as though committers don't automatically have permission to resolve issues. (See the discussion on GEOMETRY-56.) Are you able to look into this? Thanks, Matt J