You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@jackrabbit.apache.org by re...@apache.org on 2020/02/19 15:00:54 UTC

svn commit: r1874200 - in /jackrabbit/site/live/jcr: downloads.html index.html

Author: reschke
Date: Wed Feb 19 15:00:53 2020
New Revision: 1874200

URL: http://svn.apache.org/viewvc?rev=1874200&view=rev
Log:
@trivial: Site checkin for project Apache Jackrabbit Site-1.0-SNAPSHOT

Modified:
    jackrabbit/site/live/jcr/downloads.html
    jackrabbit/site/live/jcr/index.html

Modified: jackrabbit/site/live/jcr/downloads.html
URL: http://svn.apache.org/viewvc/jackrabbit/site/live/jcr/downloads.html?rev=1874200&r1=1874199&r2=1874200&view=diff
==============================================================================
--- jackrabbit/site/live/jcr/downloads.html (original)
+++ jackrabbit/site/live/jcr/downloads.html Wed Feb 19 15:00:53 2020
@@ -1,13 +1,13 @@
 <!DOCTYPE html>
 <!--
- | Generated by Apache Maven Doxia at 2020-02-14 
+ | Generated by Apache Maven Doxia at 2020-02-19 
  | Rendered using Apache Maven Fluido Skin 1.3.1
 -->
 <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
     <meta charset="UTF-8" />
     <meta name="viewport" content="width=device-width, initial-scale=1.0" />
-    <meta name="Date-Revision-yyyymmdd" content="20200214" />
+    <meta name="Date-Revision-yyyymmdd" content="20200219" />
     <meta http-equiv="Content-Language" content="en" />
     <title>Apache Jackrabbit - Downloads</title>
     <link rel="stylesheet" href="./css/apache-maven-fluido-1.3.1.min.css" />
@@ -189,7 +189,7 @@
         <ul class="breadcrumb">
                 
                     
-                  <li id="publishDate">Last Published: 2020-02-14
+                  <li id="publishDate">Last Published: 2020-02-19
                    </li>
                       
                 
@@ -524,7 +524,17 @@
 <li><a href="#archive">Release Archive</a></li>
 </ul>
 <p>Apache Jackrabbit releases are available under the <a class="externalLink" href="https://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>. See the <tt>NOTICE.txt</tt> file contained in each release artifact for applicable copyright attribution notices. Some Jackrabbit components contain external code with licenses that meet <a class="externalLink" href="https://www.apache.org/legal/resolved.html">Apache licensing policies</a>. See the <tt>LICENSE.txt</tt> file contained in each release artifact for applicable licenses.</p>
-<p><a name="v2.21" class="anchor"></a></p>
+<p><a name="oak1.4" class="anchor"></a></p>
+<div class="section">
+<h2>Apache Jackrabbit Oak 1.4.26 (February 19th, 2020)<a name="Apache_Jackrabbit_Oak_1.4.26_February_19th_2020"></a></h2>
+<p>Apache Jackrabbit Oak 1.4.26 is an incremental feature release based on and compatible with earlier stable Jackrabbit Oak 1.x releases. Jackrabbit Oak 1.4.x releases are considered stable and targeted for production use.</p>
+<p>See the <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.4.26/RELEASE-NOTES.txt">full release notes</a> for more details.</p>
+
+<ul>
+  
+<li><a class="externalLink" href="https://www.apache.org/dyn/closer.lua/jackrabbit/oak/1.4.26/jackrabbit-oak-1.4.26-src.zip">jackrabbit-oak-1.4.26-src.zip</a> (10M, source zip, <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.4.26/jackrabbit-oak-1.4.26-src.zip.asc">pgp</a>, <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.4.26/jackrabbit-oak-1.4.26-src.zip.sha512">sha512</a>)</li>
+</ul>
+<p><a name="v2.21" class="anchor"></a></p></div>
 <div class="section">
 <h2>Apache Jackrabbit 2.21.0 (February 14th, 2020)<a name="Apache_Jackrabbit_2.21.0_February_14th_2020"></a></h2>
 <p>See the <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/2.21.0/RELEASE-NOTES.txt">full release notes</a> for more details.</p>
@@ -593,16 +603,6 @@
   
 <li><a class="externalLink" href="https://www.apache.org/dyn/closer.lua/jackrabbit/oak/1.10.8/jackrabbit-oak-1.10.8-src.zip">jackrabbit-oak-1.10.8-src.zip</a> (15M, source zip, <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.10.8/jackrabbit-oak-1.10.8-src.zip.asc">pgp</a>, <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.10.8/jackrabbit-oak-1.10.8-src.zip.sha512">sha512</a>)</li>
 </ul>
-<p><a name="oak1.4" class="anchor"></a></p></div>
-<div class="section">
-<h2>Apache Jackrabbit Oak 1.4.25 (January 20th, 2020)<a name="Apache_Jackrabbit_Oak_1.4.25_January_20th_2020"></a></h2>
-<p>Apache Jackrabbit Oak 1.4.25 is an incremental feature release based on and compatible with earlier stable Jackrabbit Oak 1.x releases. Jackrabbit Oak 1.4.x releases are considered stable and targeted for production use.</p>
-<p>See the <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.4.25/RELEASE-NOTES.txt">full release notes</a> for more details.</p>
-
-<ul>
-  
-<li><a class="externalLink" href="https://www.apache.org/dyn/closer.lua/jackrabbit/oak/1.4.25/jackrabbit-oak-1.4.25-src.zip">jackrabbit-oak-1.4.25-src.zip</a> (10M, source zip, <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.4.25/jackrabbit-oak-1.4.25-src.zip.asc">pgp</a>, <a class="externalLink" href="https://www.apache.org/dist/jackrabbit/oak/1.4.25/jackrabbit-oak-1.4.25-src.zip.sha512">sha512</a>)</li>
-</ul>
 <p><a name="v2.20" class="anchor"></a></p></div>
 <div class="section">
 <h2>Apache Jackrabbit 2.20.0 (January 7th, 2020)<a name="Apache_Jackrabbit_2.20.0_January_7th_2020"></a></h2>

Modified: jackrabbit/site/live/jcr/index.html
URL: http://svn.apache.org/viewvc/jackrabbit/site/live/jcr/index.html?rev=1874200&r1=1874199&r2=1874200&view=diff
==============================================================================
--- jackrabbit/site/live/jcr/index.html (original)
+++ jackrabbit/site/live/jcr/index.html Wed Feb 19 15:00:53 2020
@@ -1,13 +1,13 @@
 <!DOCTYPE html>
 <!--
- | Generated by Apache Maven Doxia at 2020-02-14 
+ | Generated by Apache Maven Doxia at 2020-02-19 
  | Rendered using Apache Maven Fluido Skin 1.3.1
 -->
 <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
   <head>
     <meta charset="UTF-8" />
     <meta name="viewport" content="width=device-width, initial-scale=1.0" />
-    <meta name="Date-Revision-yyyymmdd" content="20200214" />
+    <meta name="Date-Revision-yyyymmdd" content="20200219" />
     <meta http-equiv="Content-Language" content="en" />
     <title>Apache Jackrabbit - Welcome to Apache Jackrabbit</title>
     <link rel="stylesheet" href="./css/apache-maven-fluido-1.3.1.min.css" />
@@ -189,7 +189,7 @@
         <ul class="breadcrumb">
                 
                     
-                  <li id="publishDate">Last Published: 2020-02-14
+                  <li id="publishDate">Last Published: 2020-02-19
                    </li>
                       
                 
@@ -466,6 +466,12 @@
 <h2>Apache Jackrabbit News<a name="Apache_Jackrabbit_News"></a></h2>
 <div class="section">
 <div class="section">
+<h4>February 19th, 2020: CVE-2020-1940: Apache Jackrabbit Oak sensitive information disclosure vulnerability (updated)<a name="February_19th_2020:_CVE-2020-1940:_Apache_Jackrabbit_Oak_sensitive_information_disclosure_vulnerability_updated"></a></h4>
+<p>We just fixed a recently reported vulnerability in Apache Jackrabbit Oak: The optional <a class="externalLink" href="https://jackrabbit.apache.org/oak/docs/security/user/expiry.html">initial password change and password expiration features</a> are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials object but does not remove it upon processing during the first phase of the authentication. In combination with additional, independent authentication mechanisms, this may lead to the new password being disclosed. Mitigation: 1.12.0 - 1.22.0 should be upgraded to <a href="downloads.html#latest">1.24.0</a>. 1.10.x should be upgraded to <a href="downloads.html#oak1.10">1.10.8</a>. 1.8.x should be upgraded to <a href="downloads.html#oak1.8">1.8.20</a>. 1.6.x should be upgraded to <a href="downloads.html#oak1.6">1.6.20</a>. 1.4.x should be upgraded to <a href="downloads.html#oak1.4">1.4
 .26</a>. For older maintained and affected branches (1.2.x), patches are available and releases will follow. See <a class="externalLink" href="https://issues.apache.org/jira/browse/OAK-8870">OAK-8870</a> for more information.</p></div>
+<div class="section">
+<h4>February 19th, 2020: Apache Jackrabbit Oak 1.4.26 released<a name="February_19th_2020:_Apache_Jackrabbit_Oak_1.4.26_released"></a></h4>
+<p>Jackrabbit Oak 1.4.26 is a patch release that contains fixes and improvements over the previous 1.4.x release. See the <a href="downloads.html#oak1.4">downloads</a> page for more details.</p></div>
+<div class="section">
 <h4>February 14th, 2020: Apache Jackrabbit 2.21.0 released<a name="February_14th_2020:_Apache_Jackrabbit_2.21.0_released"></a></h4>
 <p>Apache Jackrabbit 2.21.0 is an unstable release cut directly from trunk, with a focus on new features and other improvements. See the <a href="downloads.html#v2.21">downloads</a> page for more details.</p></div>
 <div class="section">