You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@syncope.apache.org by il...@apache.org on 2018/03/19 10:06:56 UTC

[1/3] syncope git commit: Updating downloads site page for release

Repository: syncope
Updated Branches:
  refs/heads/master 7a3dd4bc3 -> 076cc74c4


Updating downloads site page for release


Project: http://git-wip-us.apache.org/repos/asf/syncope/repo
Commit: http://git-wip-us.apache.org/repos/asf/syncope/commit/ce956589
Tree: http://git-wip-us.apache.org/repos/asf/syncope/tree/ce956589
Diff: http://git-wip-us.apache.org/repos/asf/syncope/diff/ce956589

Branch: refs/heads/master
Commit: ce95658990cd693a2eec4df6e9d76fb35295efe9
Parents: 7a3dd4b
Author: Francesco Chicchiriccò <il...@apache.org>
Authored: Tue Mar 13 15:47:06 2018 +0100
Committer: Francesco Chicchiriccò <il...@apache.org>
Committed: Mon Mar 19 10:48:06 2018 +0100

----------------------------------------------------------------------
 src/site/xdoc/downloads.xml | 120 +++++++++++++++++++--------------------
 1 file changed, 60 insertions(+), 60 deletions(-)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/syncope/blob/ce956589/src/site/xdoc/downloads.xml
----------------------------------------------------------------------
diff --git a/src/site/xdoc/downloads.xml b/src/site/xdoc/downloads.xml
index 142911a..d07e3f8 100644
--- a/src/site/xdoc/downloads.xml
+++ b/src/site/xdoc/downloads.xml
@@ -49,8 +49,8 @@ under the License.
         </div>
       </div>
 
-      <subsection name="2.0.7 Jazz">
-        <p>Release date: December 22nd 2017</p>
+      <subsection name="2.0.8 Jazz">
+        <p>Release date: March 13th 2018</p>
         <p>
           <a href="https://cwiki.apache.org/confluence/display/SYNCOPE/Jazz">Release notes</a>
         </p>
@@ -64,99 +64,99 @@ under the License.
           <tbody>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/syncope-2.0.7-source-release.zip">syncope-2.0.7-source-release.zip</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/syncope-2.0.8-source-release.zip">syncope-2.0.8-source-release.zip</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-2.0.7-source-release.zip.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-2.0.7-source-release.zip.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-2.0.7-source-release.zip.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-2.0.8-source-release.zip.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-2.0.8-source-release.zip.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-2.0.8-source-release.zip.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/syncope-standalone-2.0.7-distribution.zip">syncope-standalone-2.0.7-distribution.zip</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/syncope-standalone-2.0.8-distribution.zip">syncope-standalone-2.0.8-distribution.zip</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-standalone-2.0.7-distribution.zip.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-standalone-2.0.7-distribution.zip.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-standalone-2.0.7-distribution.zip.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-standalone-2.0.8-distribution.zip.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-standalone-2.0.8-distribution.zip.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-standalone-2.0.8-distribution.zip.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/apache-syncope-2.0.7.deb">apache-syncope-2.0.7.deb</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/apache-syncope-2.0.8.deb">apache-syncope-2.0.8.deb</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-2.0.7.deb.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-2.0.7.deb.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-2.0.7.deb.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-2.0.8.deb.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-2.0.8.deb.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-2.0.8.deb.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/apache-syncope-console-2.0.7.deb">apache-syncope-console-2.0.7.deb</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/apache-syncope-console-2.0.8.deb">apache-syncope-console-2.0.8.deb</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-console-2.0.7.deb.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-console-2.0.7.deb.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-console-2.0.7.deb.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-console-2.0.8.deb.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-console-2.0.8.deb.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-console-2.0.8.deb.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/apache-syncope-enduser-2.0.7.deb">apache-syncope-enduser-2.0.7.deb</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/apache-syncope-enduser-2.0.8.deb">apache-syncope-enduser-2.0.8.deb</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-enduser-2.0.7.deb.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-enduser-2.0.7.deb.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/apache-syncope-enduser-2.0.7.deb.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-enduser-2.0.8.deb.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-enduser-2.0.8.deb.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/apache-syncope-enduser-2.0.8.deb.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/syncope-installer-2.0.7-uber.jar">syncope-installer-2.0.7.jar</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/syncope-installer-2.0.8-uber.jar">syncope-installer-2.0.8.jar</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-installer-2.0.7-uber.jar.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-installer-2.0.7-uber.jar.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-installer-2.0.7-uber.jar.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-installer-2.0.8-uber.jar.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-installer-2.0.8-uber.jar.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-installer-2.0.8-uber.jar.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/syncope-client-cli-2.0.7.zip">syncope-client-cli-2.0.7.zip</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/syncope-client-cli-2.0.8.zip">syncope-client-cli-2.0.8.zip</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-client-cli-2.0.7.zip.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-client-cli-2.0.7.zip.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-client-cli-2.0.7.zip.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-client-cli-2.0.8.zip.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-client-cli-2.0.8.zip.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-client-cli-2.0.8.zip.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/org.apache.syncope.ide.eclipse.site-2.0.7.zip">org.apache.syncope.ide.eclipse.site-2.0.7.zip</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/org.apache.syncope.ide.eclipse.site-2.0.8.zip">org.apache.syncope.ide.eclipse.site-2.0.8.zip</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/org.apache.syncope.ide.eclipse.site-2.0.7.zip.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/org.apache.syncope.ide.eclipse.site-2.0.7.zip.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/org.apache.syncope.ide.eclipse.site-2.0.7.zip.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/org.apache.syncope.ide.eclipse.site-2.0.8.zip.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/org.apache.syncope.ide.eclipse.site-2.0.8.zip.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/org.apache.syncope.ide.eclipse.site-2.0.8.zip.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.7/syncope-ide-netbeans-2.0.7.nbm">syncope-ide-netbeans-2.0.7.nbm</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/2.0.8/syncope-ide-netbeans-2.0.8.nbm">syncope-ide-netbeans-2.0.8.nbm</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-ide-netbeans-2.0.7.nbm.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-ide-netbeans-2.0.7.nbm.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/2.0.7/syncope-ide-netbeans-2.0.7.nbm.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-ide-netbeans-2.0.8.nbm.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-ide-netbeans-2.0.8.nbm.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/2.0.8/syncope-ide-netbeans-2.0.8.nbm.sha1">sha1</a>
               </td>
             </tr>
           </tbody>
         </table>
       </subsection>
-      <subsection name="1.2.10 Intermezzo">
-        <p>Release date: January 24th 2017</p>
+      <subsection name="1.2.11 Intermezzo">
+        <p>Release date: March 13th 2018</p>
         <p>
           <a href="https://cwiki.apache.org/confluence/display/SYNCOPE/Intermezzo">Release notes</a>
         </p>
@@ -170,52 +170,52 @@ under the License.
           <tbody>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.10/syncope-1.2.10-source-release.zip">syncope-1.2.10-source-release.zip</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.11/syncope-1.2.11-source-release.zip">syncope-1.2.11-source-release.zip</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-1.2.10-source-release.zip.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-1.2.10-source-release.zip.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-1.2.10-source-release.zip.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-1.2.11-source-release.zip.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-1.2.11-source-release.zip.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-1.2.11-source-release.zip.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.10/syncope-standalone-1.2.10-distribution.zip">syncope-standalone-1.2.10-distribution.zip</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.11/syncope-standalone-1.2.11-distribution.zip">syncope-standalone-1.2.11-distribution.zip</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-standalone-1.2.10-distribution.zip.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-standalone-1.2.10-distribution.zip.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-standalone-1.2.10-distribution.zip.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-standalone-1.2.11-distribution.zip.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-standalone-1.2.11-distribution.zip.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-standalone-1.2.11-distribution.zip.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.10/apache-syncope-1.2.10.deb">apache-syncope-1.2.10.deb</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.11/apache-syncope-1.2.11.deb">apache-syncope-1.2.11.deb</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/1.2.10/apache-syncope-1.2.10.deb.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/apache-syncope-1.2.10.deb.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/apache-syncope-1.2.10.deb.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/1.2.11/apache-syncope-1.2.11.deb.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/apache-syncope-1.2.11.deb.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/apache-syncope-1.2.11.deb.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.10/apache-syncope-console-1.2.10.deb">apache-syncope-console-1.2.10.deb</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.11/apache-syncope-console-1.2.11.deb">apache-syncope-console-1.2.11.deb</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/1.2.10/apache-syncope-console-1.2.10.deb.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/apache-syncope-console-1.2.10.deb.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/apache-syncope-console-1.2.10.deb.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/1.2.11/apache-syncope-console-1.2.11.deb.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/apache-syncope-console-1.2.11.deb.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/apache-syncope-console-1.2.11.deb.sha1">sha1</a>
               </td>
             </tr>
             <tr>
               <td>
-                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.10/syncope-installer-1.2.10-uber.jar">syncope-installer-1.2.10.jar</a>
+                <a href="http://www.apache.org/dyn/closer.lua/syncope/1.2.11/syncope-installer-1.2.11-uber.jar">syncope-installer-1.2.11.jar</a>
               </td>
               <td>
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-installer-1.2.10-uber.jar.asc">asc</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-installer-1.2.10-uber.jar.md5">md5</a> 
-                <a href="https://www.apache.org/dist/syncope/1.2.10/syncope-installer-1.2.10-uber.jar.sha1">sha1</a>
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-installer-1.2.11-uber.jar.asc">asc</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-installer-1.2.11-uber.jar.md5">md5</a> 
+                <a href="https://www.apache.org/dist/syncope/1.2.11/syncope-installer-1.2.11-uber.jar.sha1">sha1</a>
               </td>
             </tr>
           </tbody>


[3/3] syncope git commit: Adding security advisories

Posted by il...@apache.org.
Adding security advisories


Project: http://git-wip-us.apache.org/repos/asf/syncope/repo
Commit: http://git-wip-us.apache.org/repos/asf/syncope/commit/076cc74c
Tree: http://git-wip-us.apache.org/repos/asf/syncope/tree/076cc74c
Diff: http://git-wip-us.apache.org/repos/asf/syncope/diff/076cc74c

Branch: refs/heads/master
Commit: 076cc74c46e99479f21ac7e81aa64a3bee8c7764
Parents: ea4fb50
Author: Francesco Chicchiriccò <il...@apache.org>
Authored: Mon Mar 19 11:05:26 2018 +0100
Committer: Francesco Chicchiriccò <il...@apache.org>
Committed: Mon Mar 19 11:06:47 2018 +0100

----------------------------------------------------------------------
 src/site/xdoc/security.xml | 96 +++++++++++++++++++++++++++++++++++++++++
 1 file changed, 96 insertions(+)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/syncope/blob/076cc74c/src/site/xdoc/security.xml
----------------------------------------------------------------------
diff --git a/src/site/xdoc/security.xml b/src/site/xdoc/security.xml
index f5b9be3..fde07b9 100644
--- a/src/site/xdoc/security.xml
+++ b/src/site/xdoc/security.xml
@@ -34,6 +34,102 @@ under the License.
 
       <p>If you want to report a vulnerability, please follow <a href="http://www.apache.org/security/">the procedure</a>.</p>
 
+      <subsection name="CVE-2018-1321: Remote code execution by administrators with report and template entitlements">	
+        <p>An administrator with report and template entitlements can use XSL Transformations (XSLT) to perform
+          malicious operations, including but not limited to file read, file write, and code execution.</p>
+
+        <p>
+          <b>Severity</b>
+        </p>
+        <p>Medium</p>
+
+        <p>
+          <b>Affects</b>
+        </p>
+        <p>
+          <ul>
+            <li>Releases prior to 1.2.11</li>
+            <li>Releases prior to 2.0.8</li>
+          </ul>
+        </p>
+        <p>The unsupported Releases 1.0.x, 1.1.x may be also affected.</p>
+
+        <p>
+          <b>Solution</b>
+        </p>
+        <p>
+          <ul>
+            <li>Syncope 1.2.x users should upgrade to 1.2.11</li>
+            <li>Syncope 2.0.x users should upgrade to 2.0.8</li>
+          </ul>          
+        </p>
+        
+        <p>
+          <b>Mitigation</b>
+        </p>
+        <p>Do not assign report and template entitlements to any administrator.</p>
+
+        <p>
+          <b>Fixed in</b>
+        </p>
+        <p>
+          <ul>
+            <li>Release 1.2.11</li>
+            <li>Release 2.0.8</li>
+          </ul>
+        </p>
+
+        <p>Read the <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1321">full CVE advisory</a>.</p>
+      </subsection>
+
+      <subsection name="CVE-2018-1322: Information disclosure via FIQL and ORDER BY sorting">	
+        <p>An administrator with user search entitlements can recover sensitive security values using the
+          <code>fiql</code> and <code>orderby</code> parameters.</p>
+
+        <p>
+          <b>Severity</b>
+        </p>
+        <p>Medium</p>
+
+        <p>
+          <b>Affects</b>
+        </p>
+        <p>
+          <ul>
+            <li>Releases prior to 1.2.11</li>
+            <li>Releases prior to 2.0.8</li>
+          </ul>
+        </p>
+        <p>The unsupported Releases 1.0.x, 1.1.x may be also affected.</p>
+
+        <p>
+          <b>Solution</b>
+        </p>
+        <p>
+          <ul>
+            <li>Syncope 1.2.x users should upgrade to 1.2.11</li>
+            <li>Syncope 2.0.x users should upgrade to 2.0.8</li>
+          </ul>          
+        </p>
+        
+        <p>
+          <b>Mitigation</b>
+        </p>
+        <p>Do not assign user search entitlements to any administrator.</p>
+
+        <p>
+          <b>Fixed in</b>
+        </p>
+        <p>
+          <ul>
+            <li>Release 1.2.11</li>
+            <li>Release 2.0.8</li>
+          </ul>
+        </p>
+
+        <p>Read the <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1322">full CVE advisory</a>.</p>
+      </subsection>
+
       <subsection name="CVE-2014-3503: Insecure Random implementations used to generate passwords">	
         <p>A password is generated for a user in Apache Syncope under certain  circumstances, when no existing password 
           is found. However, the password generation code is relying on insecure Random implementations, which means 


[2/3] syncope git commit: Updating CHANGES for release

Posted by il...@apache.org.
Updating CHANGES for release


Project: http://git-wip-us.apache.org/repos/asf/syncope/repo
Commit: http://git-wip-us.apache.org/repos/asf/syncope/commit/ea4fb50b
Tree: http://git-wip-us.apache.org/repos/asf/syncope/tree/ea4fb50b
Diff: http://git-wip-us.apache.org/repos/asf/syncope/diff/ea4fb50b

Branch: refs/heads/master
Commit: ea4fb50be96f202d730702d3f8f962baa8ba4cc5
Parents: ce95658
Author: Francesco Chicchiriccò <il...@apache.org>
Authored: Tue Mar 13 15:42:56 2018 +0100
Committer: Francesco Chicchiriccò <il...@apache.org>
Committed: Mon Mar 19 10:48:19 2018 +0100

----------------------------------------------------------------------
 CHANGES | 27 +++++++++++++++++++++++++++
 1 file changed, 27 insertions(+)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/syncope/blob/ea4fb50b/CHANGES
----------------------------------------------------------------------
diff --git a/CHANGES b/CHANGES
index 617d424..02eb768 100644
--- a/CHANGES
+++ b/CHANGES
@@ -2,6 +2,33 @@ Apache Syncope - CHANGES
 Licensed under Apache License 2.0 - http://www.apache.org/licenses/LICENSE-2.0
 --------------------------------------------------------------------------------
 
+Release Notes - Syncope - Version 2.0.8
+================================================================================
+
+** Bug
+    * [SYNCOPE-1257] - USER search by GROUP does not work if group name has spaces
+    * [SYNCOPE-1261] - When starting with empty database and no ConnInstances in Content.xml no bundles are reported as available
+    * [SYNCOPE-1263] - REST invocation with invalid JWT string returns 500
+    * [SYNCOPE-1265] - SAML 2.0 IdP cache empty until either new is imported or SAML2IdPService#list is invoked
+    * [SYNCOPE-1266] - Multivalue binary attributes leads to OutOfMemory exception
+    * [SYNCOPE-1269] - Cannot specify validator for Configuration Parameters
+    * [SYNCOPE-1272] - Export of the report always returns the result of the last execution
+    * [SYNCOPE-1275] - Add the possibiliy to delete a job
+    * [SYNCOPE-1276] - Link or assign Group from External Resource resets dynamic membership conditions
+
+** New Feature
+    * [SYNCOPE-1259] - Japanese translation for Admin console & Enduser UI
+    * [SYNCOPE-1279] - Provide live updates from running tasks and reports
+
+** Improvement
+    * [SYNCOPE-1225] - Search funcionality in Schemas
+    * [SYNCOPE-1267] - Provide check of mimetypes before generate a binary attribute preview
+    * [SYNCOPE-1274] - Report required and read-only payload properties in OpenApi spec
+    * [SYNCOPE-1280] - Better job interrupt
+
+** Task
+    * [SYNCOPE-1262] - Upgrade to Swagger UI 3.0
+
 Release Notes - Syncope - Version 2.0.7
 ================================================================================