[ANNOUNCE] Apache Traffic Server is vulnerable to various smuggle, DOS, and validation attacks

2021-11-02 Thread Bryan Call
Description: ATS is vulnerable to various smuggle, DOS, and validation attacks CVE (8.1.x and 9.1.x): CVE-2021-37147 Request Smuggling - LF line ending CVE-2021-37148 Request Smuggling - transfer encoding validation CVE-2021-37149 Request Smuggling - multiple attacks CVE-2021-41585 ATS stops accep

[ANNOUNCE] Apache Traffic Server 9.1.1 and 8.1.3 are Released

2021-11-02 Thread Bryan Call
Apache Traffic Server 9.1.1 and 8.1.3 are Released The Apache Software Foundation and the Apache Traffic Server (ATS) Project are pleased to announce the release of Apache Traffic Server 9.1.1 and 8.1.3! ATS is a high performance, scalable HTTP Intermediary and proxy cache. It is used by sever

Re: [VOTE] Release Apache Traffic Server 8.1.3 (RC1)

2021-11-02 Thread Bryan Call
The vote passes with 3 +1 votes and 0 -1 votes. I will prepare the final release. -Bryan > On Nov 2, 2021, at 11:35 AM, Evan Zelkowitz wrote: > > +1 > > On Mon, Nov 1, 2021 at 3:50 PM Bryan Call > wrote: > >> I've prepared a release for 8.1.3. The release notes ar

Re: [VOTE] Release Apache Traffic Server 8.1.3 (RC1)

2021-11-02 Thread Evan Zelkowitz
+1 On Mon, Nov 1, 2021 at 3:50 PM Bryan Call wrote: > I've prepared a release for 8.1.3. The release notes are available at: > > > https://github.com/apache/trafficserver/pulls?q=is%3Aclosed+is%3Apr+milestone%3A8.1.3 > < > https://github.com/apache/trafficserver/pulls?q=is:closed+is:pr+mileston

Re: [VOTE] Release Apache Traffic Server 9.1.1 (RC2)

2021-11-02 Thread Bryan Call
The vote passes with 3 +1 votes and 0 -1 votes. I will prepare the final release. -Bryan > On Nov 1, 2021, at 4:29 PM, Leif Hedstrom wrote: > > +1 > > — leif > > >> On Nov 1, 2021, at 3:49 PM, Bryan Call wrote: >> >> I've prepared a release for 9.1.1. The release notes are available at:

Re: [VOTE] Release Apache Traffic Server 8.1.3 (RC1)

2021-11-02 Thread Randall Meyer
+1 On Monday, November 1, 2021, 02:50:08 PM PDT, Bryan Call wrote: I've prepared a release for 8.1.3.  The release notes are available at:     https://github.com/apache/trafficserver/pulls?q=is%3Aclosed+is%3Apr+milestone%3A8.1.3

Re: [VOTE] Release Apache Traffic Server 8.1.3 (RC1)

2021-11-02 Thread Leif Hedstrom
+1 — leif > On Nov 1, 2021, at 3:49 PM, Bryan Call wrote: > > I've prepared a release for 8.1.3. The release notes are available at: > > > https://github.com/apache/trafficserver/pulls?q=is%3Aclosed+is%3Apr+milestone%3A8.1.3 > >