From commits-return-6686-apmail-continuum-commits-archive=continuum.apache.org@continuum.apache.org Fri Nov 30 05:56:54 2012 Return-Path: X-Original-To: apmail-continuum-commits-archive@www.apache.org Delivered-To: apmail-continuum-commits-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id DF09CE7B7 for ; Fri, 30 Nov 2012 05:56:54 +0000 (UTC) Received: (qmail 13179 invoked by uid 500); 30 Nov 2012 05:56:54 -0000 Delivered-To: apmail-continuum-commits-archive@continuum.apache.org Received: (qmail 13127 invoked by uid 500); 30 Nov 2012 05:56:53 -0000 Mailing-List: contact commits-help@continuum.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@continuum.apache.org Delivered-To: mailing list commits@continuum.apache.org Received: (qmail 13114 invoked by uid 99); 30 Nov 2012 05:56:53 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 30 Nov 2012 05:56:53 +0000 X-ASF-Spam-Status: No, hits=-2000.0 required=5.0 tests=ALL_TRUSTED X-Spam-Check-By: apache.org Received: from [140.211.11.4] (HELO eris.apache.org) (140.211.11.4) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 30 Nov 2012 05:56:42 +0000 Received: from eris.apache.org (localhost [127.0.0.1]) by eris.apache.org (Postfix) with ESMTP id C97922388A66; Fri, 30 Nov 2012 05:56:19 +0000 (UTC) Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: svn commit: r1415501 [3/4] - in /continuum/site-publish: ./ css/ development/ Date: Fri, 30 Nov 2012 05:56:17 -0000 To: commits@continuum.apache.org From: brett@apache.org X-Mailer: svnmailer-1.0.8-patched Message-Id: <20121130055619.C97922388A66@eris.apache.org> X-Virus-Checked: Checked by ClamAV on apache.org Modified: continuum/site-publish/features.html URL: http://svn.apache.org/viewvc/continuum/site-publish/features.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/features.html (original) +++ continuum/site-publish/features.html Fri Nov 30 05:56:15 2012 @@ -20,7 +20,7 @@ - + @@ -31,7 +31,7 @@ pageTracker._trackPageview();

@@ -204,23 +204,7 @@ pageTracker._trackPageview();
-

Continuum Features

-

Continuum offers the following features:

-
  1. Easy installation : Download the standalone application and run it or deploy the Continuum WAR in your servlet container. Read more
  2. -
  3. Easy Configuration : Project's builds are auto-configured but they can be configured easily with the web interface
  4. -
  5. SCM support : CVS, Subversion, Clearcase, Perforce, Starteam, Visual Source Safe, CM Synergy, Bazaar, Mercurial are supported
  6. -
  7. Change set support : For each build result, Continuum print all SCM changes (commit authors, commit logs, modified files)
  8. -
  9. Build notification : Mail, Jabber and Google Talk, MSN, IRC, report deployment with wagon
  10. -
  11. Build tool support : Maven 1 and 2, ANT, shell scripts
  12. -
  13. External Access : External tools can interact with Continuum with XMLRPC API. Read more
  14. -
  15. Build type : Manual, scheduled and push (with xmlrpc) build technique are supported
  16. -
  17. Build template : Users can define default build templates to use by project type
  18. -
  19. Build queue : Users can view all projects in the queue and interrupt some builds
  20. -
  21. Distributed Builds : Projects can be distributed and built in multiple build agents
  22. -
  23. Parallel Builds : Projects can be built simultaneously or concurrently locally using multiple build queues.
  24. -
-
- +

Continuum Features

Continuum offers the following features:

  1. Easy installation : Download the standalone application and run it or deploy the Continuum WAR in your servlet container. Read more
  2. Easy Configuration : Project's builds are auto-configured but they can be configured easily with the web interface
  3. SCM support : CVS, Subversion, Clearcase, Perforce, Starteam, Visual Source Safe, CM Synergy, Bazaar, Mercurial are supported
  4. Change set support : For each build result, Continuum print all SCM changes (commit authors, commit logs, modified files)
  5. Build notification : Mail, Jabber and Google Talk, MSN, IRC, report deployment with wagon
  6. Build tool support : Maven 1 and 2, ANT, shell scripts
  7. External Access : Ext ernal tools can interact with Continuum with XMLRPC API. Read more
  8. Build type : Manual, scheduled and push (with xmlrpc) build technique are supported
  9. Build template : Users can define default build templates to use by project type
  10. Build queue : Users can view all projects in the queue and interrupt some builds
  11. Distributed Builds : Projects can be distributed and built in multiple build agents
  12. Parallel Builds : Projects can be built simultaneously or concurrently locally using multiple build queues.
@@ -228,7 +212,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/getting-help.html URL: http://svn.apache.org/viewvc/continuum/site-publish/getting-help.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/getting-help.html (original) +++ continuum/site-publish/getting-help.html Fri Nov 30 05:56:15 2012 @@ -21,7 +21,7 @@ - + @@ -32,7 +32,7 @@ pageTracker._trackPageview();

@@ -205,31 +205,7 @@ pageTracker._trackPageview();
-

Getting Help

-

So something didn't work as you expected it to? You think that Continuum is broken. What should you do?

-

Here's an list of actions that you can take:

-
-

Ask on the user list

-

Our community is very helpful, just ask it the right way. See the references section, at the end of this page, for info on how to do that. Subscribe to the users-list and describe your problem there. Don't expect to get an answer right away. Sometimes it takes a couple of days.

-
-

Submit an issue

-

If it turns out that there is indeed something wrong with Continuum, you should report it to our issue management system JIRA.

-

First of all you need to create an account in JIRA. This is so that we can communicate with you while we work together on the issue. Go here to create an account if you don't already have one.

-

How?

-

Just describing the problem is not enough. It takes a developer a lot of time to make a usable environment to even attempt to assess the problem. Issues that states problems without something usable to try out will be closed as incomplete.

-

Please attach all you can (screen copy, logs, environment description...), that we'll help us to understand your issue. We appreciate reports, but if you don't have something usable for us it's incredibly hard for us to manage the issues.

-

What we like best are patches that fixes the problem. If you want to create a patch for an issue please read this document first.

-
-
- -
- +

Getting Help

So something didn't work as you expected it to? You think that Continuum is broken. What should you do?

Here's an list of actions that you can take:

Search the user-list archives

Someone else might have experienced the same problem as you before. A list of mail-archives can be found on this page. Please search one of them before going any further.

Ask on the user list

Our community is very helpful, just ask it the right way. See the references section, at the end of this page, for info on how to do that. Subscribe to the users-list and describe your problem there. Don't expect to get an answer right away. Sometimes it takes a couple of days.

Submit an issue

If it turns out that there is indeed something wrong with Continuum, you should report it to our issue management system JIRA.

First of all you need to create an account in JIRA. This is so that we can communicate with you while we work together on the issue. Go here to create an account if you don't already have one.

How?

Just describing the problem is not enough. It takes a developer a lot of time to make a usable environment to even attempt to assess the problem. Issues that states problems without something usable to try out will be closed as incomplete.

Please attach all you can (screen copy, logs, environment description...), that we'll help us to understand your issue. We appreciate reports, but if you don't have something usab le for us it's incredibly hard for us to manage the issues.

What we like best are patches that fixes the problem. If you want to create a patch for an issue please read this document first.

@@ -237,7 +213,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/guide-helping.html URL: http://svn.apache.org/viewvc/continuum/site-publish/guide-helping.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/guide-helping.html (original) +++ continuum/site-publish/guide-helping.html Fri Nov 30 05:56:15 2012 @@ -22,7 +22,7 @@ - + @@ -33,7 +33,7 @@ pageTracker._trackPageview();

@@ -206,51 +206,7 @@ pageTracker._trackPageview();
-

Guide to helping with Continuum

-

As with any open source project, there are several ways you can help:

-
  • Join the mailing list and answer other user's questions
  • -
  • Report bugs, feature requests and other issues in the issue tracking application.
  • -
  • Build Continuum for yourself, in order to fix bugs.
  • -
  • Submit patches to reported issues (both those you find, or that others have filed)
  • -
  • Developer reference docs for the latest snapshot can be found starting here.
  • -
  • Javadoc is available, including UMLGraph diagrams at the class and package level.
  • -
  • Help with the documentation by pointing out areas that are lacking or unclear, and if you are so inclined, submitting patches to correct it. You can quickly contribute rough thoughts to the wiki, or you can volunteer to help collate and organise information that is already there.
  • -
-

Your participation in the community is much appreciated!

-
-

Why Would I Want to Help?

-

There are several reasons these are good things.

-
  • By answering other people's questions, you can learn more for yourself
  • -
  • By submitting your own fixes, they get incorporated faster
  • -
  • By reporting issues, you ensure that bugs don't get missed, or forgotten
  • -
  • You are giving back to a community that has given you software for free
  • -
-
-

How do I Join the Project?

-

Projects at Apache operate under a meritocracy, meaning those that the developers notice participating to a high extent will be invited to join the project as a committer.

-

This is as much based on personality and ability to work with other developers and the community as it is with proven technical ability. Being unhelpful to other users, or obviously looking to become a committer for bragging rights and nothing else is frowned upon, as is asking to be made a committer without having contributed sufficiently to be invited.

-
-

Developer's Conventions

-

There are a number of conventions used in the project, which contributors and developers alike should follow for consistency's sake.

- -
-

Resources for contributors

- -
- - +

Guide to helping with Continuum

As with any open source project, there are several ways you can help:

  • Join the mailing list and answer other user's questions
  • Report bugs, feature requests and other issues in the issue tracking application.
  • Build Continuum for yourself, in order to fix bugs.
  • Submit patches to reported issues (both those you find, or that others have filed)
  • Developer reference docs for the latest snapshot can be found starting here.
  • Javadoc is available, including UMLGraph diagrams at the class and package level.
  • Help with the documentation by pointing out areas that are lacking or unclear, and if you are so inclined, submitting patches to correct it. You can quickly contribute rough thoughts to the wiki, or you can volunteer to help collate and organise information that is already there.

Your participation in the community is much appreciated!

Why Would I Want to Help?

There are several reasons these are good things.

  • By answering other people's questions, you can learn more for yourself
  • By submitting your own fixes, they get incorporated faster
  • By reporting issues, you ensure that bugs don't get missed, or forgotten
  • You are giving back to a community that has given you software for free

How do I Join the Project?

Pr ojects at Apache operate under a meritocracy, meaning those that the developers notice participating to a high extent will be invited to join the project as a committer.

This is as much based on personality and ability to work with other developers and the community as it is with proven technical ability. Being unhelpful to other users, or obviously looking to become a committer for bragging rights and nothing else is frowned upon, as is asking to be made a committer without having contributed sufficiently to be invited.

Developer's Conventions

There are a number of conventions used in the project, which contributors and developers alike should follow for consistency's sake.

Resources for contributors

@@ -258,7 +214,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/index.html URL: http://svn.apache.org/viewvc/continuum/site-publish/index.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/index.html (original) +++ continuum/site-publish/index.html Fri Nov 30 05:56:15 2012 @@ -12,7 +12,8 @@ - Continuum - Welcome to Continuum + Continuum - + Welcome to Continuum - + @@ -31,7 +32,7 @@ pageTracker._trackPageview();

@@ -204,8 +205,28 @@ pageTracker._trackPageview();
- + + $('#features').find('img').attr('height','120'); $('.lightbox').lightbox(); }); +]]> + + +

Apache Continuum

+

Continuous Integration and Build Server

-

Apache Continuum

Continuous Integration and Build Server

+

Apache Continuum is an enterprise-ready continuous integration server with features such as automated builds, release management, role-based security, and integration with popular build tools and source control @@ -226,36 +252,104 @@ pageTracker._trackPageview(); to put control of releases in the hands of developers, Continuum can help you improve quality and maintain a consistent build environment.

-

- Follow us on Twitter @apachecontinuum to get the latest news and updates! +

+ Follow us on Twitter @apachecontinuum to get the latest news and updates!

-

Continuum 1.3.8 (GA)
-18 September 2011 -
-Release Notes | Documentation

-

Continuum 1.4.0 (Beta)
-6 May 2010 -
-Release Notes | Documentation

-

Apache License 2.0

-

Security Vulnerabilities

-
+ +
+ +

+ Continuum 1.3.8 (GA)
18 September 2011 +
Release Notes | Documentation +

+

+ Continuum 1.4.0 (Beta)
6 May 2010 +
Release Notes | Documentation +

+

+ Apache License 2.0 +

+

+ Security Vulnerabilities +

+
+ + + + + +
+ +

+ +
Screenshot Tour
+ + + +
+

+

+ Live Demo +

+

+ Articles +

+
+ + +
@@ -263,7 +357,7 @@ Screenshot Tour
© - 2003-2011 + 2003-2012 The Apache Software Foundation @@ -280,4 +374,4 @@ Screenshot Tour - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();

@@ -174,9 +174,9 @@ pageTracker._trackPageview(); + - @@ -189,6 +189,10 @@ pageTracker._trackPageview();
-

Overview

-This project uses JIRA a J2EE-based, issue tracking and project management application.
-

Issue Tracking

-

Issues, bugs, and feature requests should be submitted to the following issue tracking system for this project.

- -
- +

Overview

This project uses JIRA a J2EE-based, issue tracking and project management application.

Issue Tracking

Issues, bugs, and feature requests should be submitted to the following issue tracking system for this project.

@@ -240,7 +233,7 @@ This project uses
© - 2003-2011 + 2003-2012 The Apache Software Foundation @@ -257,4 +250,4 @@ This project uses - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();

@@ -203,22 +203,7 @@ pageTracker._trackPageview();
-

Known Issues and Errata ------

-
-

Known Issues and Errata

-
-

Continuum 1.4.0 (Beta)

-

Known Issues

-

CONTINUUM-2188 has been partially implemented in this release. While the Update Policy field now appears in the Build Definition form, it is currently undocumented.

-
-
-
- +

Known Issues and Errata ------

Known Issues and Errata

Continuum 1.3.8 (GA)

Known Issues

  • For a list of all JIRA issues reported against Continuum 1.3.8, click here.

Continuum 1.4.0 (Beta)

Known Issues

CONTINUUM-2188 has been partially implemented in this release. While the Update Policy field now appears in the Build Definition form, it is currently undocumented.

@@ -226,7 +211,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/license.html URL: http://svn.apache.org/viewvc/continuum/site-publish/license.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/license.html (original) +++ continuum/site-publish/license.html Fri Nov 30 05:56:15 2012 @@ -19,7 +19,7 @@ @import url("./css/site.css"); - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();

@@ -174,11 +174,11 @@ pageTracker._trackPageview(); - - + + @@ -189,6 +189,10 @@ pageTracker._trackPageview();
-

Overview

-

Typically the licenses listed for the project are that of the project itself, and not of dependencies.

-
-

Project License

-

The Apache Software License, Version 2.0

-
+        

Overview

Typically the licenses listed for the project are that of the project itself, and not of dependencies.

Project License

The Apache Software License, Version 2.0

                                  Apache License
                            Version 2.0, January 2004
                         http://www.apache.org/licenses/
@@ -432,11 +427,7 @@ pageTracker._trackPageview();
    WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    See the License for the specific language governing permissions and
    limitations under the License.
-
-
-
-
- +
@@ -444,7 +435,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/mail-lists.html URL: http://svn.apache.org/viewvc/continuum/site-publish/mail-lists.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/mail-lists.html (original) +++ continuum/site-publish/mail-lists.html Fri Nov 30 05:56:15 2012 @@ -19,7 +19,7 @@ @import url("./css/site.css"); - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();

@@ -176,9 +176,9 @@ pageTracker._trackPageview(); + - @@ -189,6 +189,10 @@ pageTracker._trackPageview();
-

Project Mailing Lists

-

These are the mailing lists that have been established for this project. For each list, there is a subscribe, unsubscribe, and an archive link.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
NameSubscribeUnsubscribePostArchiveOther Archives
Continuum User ListSubscribeUnsubscribePostmail-archives.apache.orgwww.mail-archive.com
www.nabble.com
continuum.markmail.org
Continuum Development ListSubscribeUnsubscribePostmail-archives.apache.orgwww.mail-archive.com
www.nabble.com
markmail.org
Continuum Commits ListSubscribeUnsubscribe-mail-archives.apache.orgwww.mail-archive.com
markmail.org
Continuum Issues ListSubscribeUnsubscribe-mail-archives.apache.orgwww.mail-archive.com
markmail.org
www.nabble.com
-
- +

Project Mailing Lists

These are the mailing lists that have been established for this project. For each list, there is a subscribe, unsubscribe, and an archive link.

< td>www.nabble.com
NameSubscribeUnsubscribePostArchiveOther Archives
Continuum User ListSubscribeUnsubscribePostmail-archives.apache.orgwww.mail-archive.com
www.nabble.com
continuum.markmail.org
Continuum Development ListSubscribeUnsubscribePostmail-archives.apache.orgwww.mail-archive.com
markmail.org
Continuum Commits ListSubscribeUnsubscribe-mail-archives.apache.orgwww.mail-archive.com
markmail.org
Continuum Issues ListSubscribeUnsubscribe-mail-archives.apache.orgwww.mail-archive.com
markmail.org
www.nabble.com
@@ -321,7 +233,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/privacy-policy.html URL: http://svn.apache.org/viewvc/continuum/site-publish/privacy-policy.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/privacy-policy.html (original) +++ continuum/site-publish/privacy-policy.html Fri Nov 30 05:56:15 2012 @@ -20,7 +20,7 @@ - + @@ -31,7 +31,7 @@ pageTracker._trackPageview();

@@ -204,19 +204,7 @@ pageTracker._trackPageview();
-

Privacy Policy

-

Information about your use of this website is collected using server access logs and a tracking cookie. The collected information consists of the following:

-
  1. The IP address from which you access the website;
  2. -
  3. The type of browser and operating system you use to access our site;
  4. -
  5. The date and time you access our site;
  6. -
  7. The pages you visit; and
  8. -
  9. The addresses of pages from where you followed a link to our site.
  10. -
-

Part of this information is gathered using a tracking cookie set by the Google Analytics service and handled by Google as described in their privacy policy. See your browser documentation for instructions on how to disable the cookie if you prefer not to share this data with Google.

-

We use the gathered information to help us make our site more useful to visitors and to better understand how and when our site is used. We do not track or collect personally identifiable information or associate gathered data with any personally identifying information from other sources.

-

By using this website, you consent to the collection of this data in the manner and for the purpose described above.

-
- +

Privacy Policy

Information about your u se of this website is collected using server access logs and a tracking cookie. The collected information consists of the following:

  1. The IP address from which you access the website;
  2. The type of browser and operating system you use to access our site;
  3. The date and time you access our site;
  4. The pages you visit; and
  5. The addresses of pages from where you followed a link to our site.

Part of this information is gathered using a tracking cookie set by the Google Analytics service and handled by Google as described in their privacy policy. See your browser documentation for instructions on how to disable the cookie if you prefer not to share this data with Google.

We use the gathered information to help us make our site more useful to visitors and to be tter understand how and when our site is used. We do not track or collect personally identifiable information or associate gathered data with any personally identifying information from other sources.

By using this website, you consent to the collection of this data in the manner and for the purpose described above.

@@ -224,7 +212,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/project-info.html URL: http://svn.apache.org/viewvc/continuum/site-publish/project-info.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/project-info.html (original) +++ continuum/site-publish/project-info.html Fri Nov 30 05:56:15 2012 @@ -19,7 +19,7 @@ @import url("./css/site.css"); - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();
-

Project Information

-

This document provides an overview of the various documents and links that are part of this project's general information. All of this content is automatically generated by Maven on behalf of the project.

-

Overview

- - - - - - - - - - - - - - - - - - -
DocumentDescription
Issue TrackingThis is a link to the issue management system for this project. Issues (bugs, features, change requests) can be created and queried using this link.
Mailing ListsThis document provides subscription and archive information for this project's mailing lists.
Project LicenseThis is a link to the definitions of project licenses.
Project TeamThis document provides information on the members of this project. These are the individuals who have contributed to the project in one form or another.
Source RepositoryThis is a link to the online source repository that can be viewed via a web browser.
-
-
- +

Project Information

This document provides an overview of the various documents and links that are part of this project's general information. All of this content is automatically generated by Maven on behalf of the project.

Overview

DocumentDescription
Project LicenseThis is a link to the definitions of project licenses.
Issue TrackingThis is a link to the issue management system for this project. Issues (bugs, features, change requests) can be created and queried using this link.
Mailing ListsThis document provides subscription and archive information for this project's mailing lists.
Project TeamThis document provides information on the members of this project. These are the individuals who have contributed to the project in one form or another.
Source RepositoryThis is a link to the online source repository that can be viewed via a web browser.
@@ -257,7 +233,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/security.html URL: http://svn.apache.org/viewvc/continuum/site-publish/security.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/security.html (original) +++ continuum/site-publish/security.html Fri Nov 30 05:56:15 2012 @@ -19,7 +19,7 @@ @import url("./css/site.css"); - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();

@@ -203,26 +203,7 @@ pageTracker._trackPageview();
-

Security Vulnerabilities

-

Please note that binary patches are not produced for individual vulnerabilities. To obtain the binary fix for a particular vulnerability you should upgrade to an Apache Continuum version where that vulnerability has been fixed.

-

CVE-2011-0533: Apache Continuum cross-site scripting vulnerability

-

A request that included a specially crafted request parameter could be used to inject arbitrary HTML or Javascript into the Continuum user management page and project details pages. This fix is available in version 1.3.7 of Apache Continuum. All users must upgrade to this version (or higher).

-

Versions Affected:

-
  • Continuum 1.3.6
  • -
  • Continuum 1.4.0 (Beta)
  • -
  • The unsupported versions Continuum 1.1 - 1.2.3.1 are also affected.
  • -
-
-

CVE-2010-3449: Apache Continuum CSRF vulnerability

-

Apache Continuum doesn't check which form sends credentials. An attacker can create a specially crafted page and force Continuum administrators to view it and change their credentials. To fix this, a referrer check was added to the security interceptor for all secured actions. A prompt for the administrator's password when changing a user account was also set in place. This fix is available in version 1.3.7 of Apache Continuum. All users must upgrade to this version (or higher).

-

Versions Affected:

-
  • Continuum 1.3.6
  • -
  • Continuum 1.4.0 (Beta)
  • -
  • The unsupported versions Continuum 1.1 - 1.2.3.1 are also affected.
  • -
-
-
- +

Security Vulnerabilities

Please note that binary patches are not produced for individual vulnerabilities. To obtain the binary fix for a particular vulnerability you should upgrade to an Apache Continuum version where that vulnerability has been fixed.

CVE-2011-0533: Apache Continuum cross-site scripting vulnerability

A request that included a specially crafted request parameter could be used to inject arbitrary HTML or Javascript into the Continuum user management page and project details pages. This fix is available in version 1.3.7 of Apache Continuum. All users must upgrade to this version (or higher).

Versions Affected:

  • Continuum 1.3.6
  • Continuum 1.4.0 (Beta)
  • The unsupported versions Continuum 1.1 - 1 .2.3.1 are also affected.

CVE-2010-3449: Apache Continuum CSRF vulnerability

Apache Continuum doesn't check which form sends credentials. An attacker can create a specially crafted page and force Continuum administrators to view it and change their credentials. To fix this, a referrer check was added to the security interceptor for all secured actions. A prompt for the administrator's password when changing a user account was also set in place. This fix is available in version 1.3.7 of Apache Continuum. All users must upgrade to this version (or higher).

Versions Affected:

  • Continuum 1.3.6
  • Continuum 1.4.0 (Beta)
  • The unsupported versions Continuum 1.1 - 1.2.3.1 are also affected.
@@ -230,7 +211,7 @@ pageTracker._trackPageview();
- + \ No newline at end of file Modified: continuum/site-publish/source-repository.html URL: http://svn.apache.org/viewvc/continuum/site-publish/source-repository.html?rev=1415501&r1=1415500&r2=1415501&view=diff ============================================================================== --- continuum/site-publish/source-repository.html (original) +++ continuum/site-publish/source-repository.html Fri Nov 30 05:56:15 2012 @@ -19,7 +19,7 @@ @import url("./css/site.css"); - + @@ -30,7 +30,7 @@ pageTracker._trackPageview();
-

Overview

-This project uses Subversion to manage its source code. Instructions on Subversion use can be found at http://svnbook.red-bean.com/.
-

Web Access

-

The following is a link to the online source repository.

- -
-

Anonymous access

-

The source can be checked out anonymously from SVN with this command:

-
$ svn checkout http://svn.apache.org/repos/asf/continuum/trunk continuum
-
-
-

Developer access

-

Everyone can access the Subversion repository via HTTP, but Committers must checkout the Subversion repository via HTTPS.

-
$ svn checkout https://svn.apache.org/repos/asf/continuum/trunk continuum
-
-

To commit changes to the repository, execute the following command to commit your changes (svn will prompt you for your password)

-
$ svn commit --username your-username -m "A message"
-
-
-

Access from behind a firewall

-

For those users who are stuck behind a corporate firewall which is blocking HTTP access to the Subversion repository, you can try to access it via the developer connection:

-
$ svn checkout https://svn.apache.org/repos/asf/continuum/trunk continuum
-
-
-

Access through a proxy

-

The Subversion client can go through a proxy, if you configure it to do so. First, edit your "servers" configuration file to indicate which proxy to use. The file's location depends on your operating system. On Linux or Unix it is located in the directory "~/.subversion". On Windows it is in "%APPDATA%\Subversion". (Try "echo %APPDATA%", note this is a hidden directory.)

-

There are comments in the file explaining what to do. If you don't have that file, get the latest Subversion client and run any command; this will cause the configuration directory and template files to be created.

-

Example: Edit the 'servers' file and add something like:

-
[global]
+        

Overview

This project uses Subversion to manage its source code. Instructions on Subversion use can be found at http://svnbook.red-bean.com/.

Web Access

The following is a link to the online source repository.

Anonymous access

The source can be checked out anonymously from SVN with this command:

$ svn checkout http://svn.apache.org/repos/asf/continuum/trunk continuum

Developer access

Everyone c an access the Subversion repository via HTTP, but Committers must checkout the Subversion repository via HTTPS.

$ svn checkout https://svn.apache.org/repos/asf/continuum/trunk continuum

To commit changes to the repository, execute the following command to commit your changes (svn will prompt you for your password)

$ svn commit --username your-username -m "A message"

Access from behind a firewall

For those users who are stuck behind a corporate firewall which is blocking HTTP access to the Subversion repository, you can try to access it via the developer connection:

$ svn checkout https://svn.apache.org/repos/asf/continuum/trunk continuum

Access through a proxy

The Subversion client can go thro ugh a proxy, if you configure it to do so. First, edit your "servers" configuration file to indicate which proxy to use. The file's location depends on your operating system. On Linux or Unix it is located in the directory "~/.subversion". On Windows it is in "%APPDATA%\Subversion". (Try "echo %APPDATA%", note this is a hidden directory.)

There are comments in the file explaining what to do. If you don't have that file, get the latest Subversion client and run any command; this will cause the configuration directory and template files to be created.

Example: Edit the 'servers' file and add something like:

[global]
 http-proxy-host = your.proxy.name
 http-proxy-port = 3128
-
-
-
- +
@@ -268,7 +236,7 @@ http-proxy-port = 3128
- + \ No newline at end of file