oss-sec mailing list archives

[ANNOUNCE][CVE-2016-0779] Apache TomEE 1.7.4 and 7.0.0-M3 releases


From: Romain Manni-Bucau <rmannibucau () apache org>
Date: Tue, 15 Mar 2016 22:24:14 +0100

Note: resending this mail since it seems some recipients have been rejected

The Apache Team Team is pleased to announce the availability of:

Apache TomEE 7.0.0-M3 and 1.7.4

When downloading, please verify signatures using the KEYS file available at:
http://www.apache.org/dist/tomee

Maven artifacts are also available in the central Maven repository.

The releases are primarily security releases to address CVE-2016-0779, EJBd
protocol allows to exploit 0-day vulnerability in all previous releases.


The Apache TomEE Team

Current thread: