Re: [VOTE] Release Apache Commons BCEL 6.7.0 based on RC1

2022-12-03 Thread Gary Gregory
Please take the time to review and vote on this RC. Gary On Fri, Dec 2, 2022 at 8:54 AM Gary Gregory wrote: > > ping ;-) > > On Mon, Nov 28, 2022 at 2:12 PM Bruno Kinoshita wrote: > > > >[x] +1 Release these artifacts > > > > Building OK from tag with: > > > > Apache Maven 3.8.5 (3599d3414f

CVE-2021-37533: Apache Commons Net's FTP client trusts the host from PASV response by default

2022-12-03 Thread Gary D. Gregory
Severity: low Description: Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to l