activemq-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Dejan Bosanac <de...@nighttale.net>
Subject Re: [ANNOUNCE] Apache ActiveMQ 5.13.0 Released
Date Mon, 07 Dec 2015 10:04:21 GMT
Hi Claus,

restrictions were necessary for the CVE that was reported. We’re about to
disclose it fully now after the release.

AFAIK the change should not affect ObjectMessages in general, just the
cases where those objects are serialized/unserialized inside of the broker,
like web console or stomp transformations. I’ll create a proper docs for
the change now and the security aspect of it and we can see later whet else
we can do to improve the user experience.

Are there any Camel related tests that fails due to this change? I can take
a look at that as well.


Regards
--
Dejan Bosanac
about.me/dejanb

On Sat, Dec 5, 2015 at 11:19 AM, Claus Ibsen <claus.ibsen@gmail.com> wrote:

> I really think you guys should add something about those object
> serialization resitrcitions. Any end users that uses java objects over
> JMS is affected. Nothing works anymore.
>
> Its because of
> https://issues.apache.org/jira/browse/AMQ-6013
>
> So there should be some text in the release notes, and ideally AMQ
> broker / client should have some kind of INFO logging that openwire
> with objects is restricted or not. Otherwise its even harder for end
> users to spot what is going on.
>
>
>
> On Fri, Dec 4, 2015 at 3:57 PM, Timothy Bish <tabish121@gmail.com> wrote:
> > It's probably a good idea to add a new page in the "New Features" section
> > on the site to cover the additions in 5.13.0.  I know you added the
> 'auto'
> > transport along with some other work for some additional metrics etc, all
> > good things that would be nice to advertise a bit.
> >
> > See: http://activemq.apache.org/new-features.html
> >
> > On Thu, Dec 3, 2015 at 3:51 PM, Christopher Shannon <
> > christopher.l.shannon@gmail.com> wrote:
> >
> >> Hi everyone,
> >>
> >> Apache ActiveMQ 5.13.0 has now been released.
> >>
> >> This release contains a number of resolved issues and new features since
> >> the 5.12.1 release.
> >>
> >> A list of issues resolved in this release is available here:
> >>
> >>
> https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12329848
> >>
> >> The Wiki page for the release is here:
> >> http://activemq.apache.org/activemq-5130-release.html
> >>
> >> API documentation for 5.12.1 is located here:
> >> http://activemq.apache.org/maven/5.13.0/apidocs/index.html
> >>
> >
> >
> >
> > --
> > --
> > Tim Bish
>
>
>
> --
> Claus Ibsen
> -----------------
> http://davsclaus.com @davsclaus
> Camel in Action 2: https://www.manning.com/ibsen2
>

Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message