SlideShare a Scribd company logo
Project + Community Services
The Apache Way
slides revision: 2017-12-06 - photos: Adobe Stock, unless otherwise specified
Emmanuel Lécharny - @elecharny_tek

Apache Software Foundation Member

Software Architect, Symas
Bertrand Delacrétaz - @bdelacretaz

Member of the Board of Directors, Apache Software Foundation

Principal Scientist, Adobe Research Switzerland
Paris Open Source Summit 2017 - Community Summit
What?
The ASF’s Mission
The Apache Software Foundation (ASF) is a 

US 501(c)(3) charitable organization.

Its mission is to provide Open Source software for
the public good. 

We do this by providing services and support for
many like-minded software project communities of
individuals who choose to join the ASF.
https://www.apache.org/foundation/
A neutral space in which projects which
are independent from any corporate
influence can prosper and create Open
Source software for the public good.
Under the business-friendly

Apache License 2.0
photos: http://archive.apachecon.com/c/
About 300 top-level projects, 50 in incubation and 40 in attic.apache.org

Clean retirement is part of the ASF project’s lifecycle
Which parts of the value chain?
Documentation

Marketing

Packaging
Configuration

Helpdesk

Operations
source code product system
Architecture
Development
Tests unitaires
Write source code, distribute and document it…that’s all.
Services?
Neutral

independent space
Nobody can pull the plug…
sim
ple, solid
infrastructure
build
track
talk
code
on to the next 50 years…
com
m
unity

best practices
legal shield

+
services
Tradem
arks
Value

Chain?
Value chain?
source code product system
Write source code, distribute and document it…

that’s all.
The ASF’s services are primarily meant for its projects
and developers - users will need some assembly.
Example: security at the ASF
-------- Forwarded Message --------

Subject: Command Injection through LDAP CSV export

Date: Mon, 30 Nov 2015 00:12:52 +0500

From: xxx@gmail.com>

To: security@apache.org



Hello there Apache team,



This is Whitehat and i would like to report a command injection vulnerability in

the Apache <project> CSV export feature described in

https://<project>.apache.org/<project>users-guide/tools_csvexport_wizard.html



The "CSV export" feature of Apache Activity records that sends out does not properly 

"escape" fields. This allows malicious users to turn the editable fields into active content 

so when that when users downloads the ticket data csv and opens it,

the active content gets executed. 



Mitigation

Ensure all fields are properly "escaped" before returning the CSV file to the user.
ALARM


all hands
on
deck!
Dear Apache <project> PMC,



The attached security vulnerability report has been received

by the Apache Security Team and is being passed to you

for action.



Please take careful note of the following:

- This information is private and should be treated accordingly. The

issue must not be discussed on a public mailing list, it must not

be added to a public bug tracker, etc.

- The <project> PMC is responsible for resolving this issue. The

security team is here to provide help and advice but the

responsibility to do the work lies with the <project> PMC.



You may find the "ASF Project Security for Committers" [1] a useful

reference. This e-mail represents step 3 of that process. 

Step 4 should be completed asap.



Kind regards,

Mark, for the Apache Security Team

[1] http://www.apache.org/security/committers.html
security@
apache

->
project
ASF security process
Due diligence: your business - your responsibility !
Don’t blame OSS for not doing your job…

Read the OSS “fine print”…

Don’t you love those

security reports?
“12. DISCLAIMER OF WARRANTY.

The software is licensed “as-is.” You bear the risk of using it. XXX gives

no express warranties, guarantees or conditions.”

(where XXX is a closed source vendor…)
@elecharny_tek

hrabal.blogspot.fr
@bdelacretaz

grep.codeconsult.ch

More Related Content

PDF
Asynchronous Decision Making - FOSS Backstage 2017
PPTX
Using Docker to boost your development experience with Drupal
PPT
Open Source Shareware Freeware
PDF
DevOps Culture & Methodology Intro
PDF
Open Source at scale: the Apache Software Foundation
PDF
Running Successful Open Source Projects
PDF
Apache: Code, Community and Open Source
PPTX
Opensource development and apache software foundation
Asynchronous Decision Making - FOSS Backstage 2017
Using Docker to boost your development experience with Drupal
Open Source Shareware Freeware
DevOps Culture & Methodology Intro
Open Source at scale: the Apache Software Foundation
Running Successful Open Source Projects
Apache: Code, Community and Open Source
Opensource development and apache software foundation

Similar to Project and Community Services the Apache Way (20)

PDF
Craig The apache Way
PDF
The Apache Way (And How Not to Break Builds!)
PPTX
Security in the age of open source - Myths and misperceptions
PPTX
Geecon 2017 Anatomy of Java Vulnerabilities
PDF
The Apache Way: A Proven Way Toward Success
PPTX
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
PDF
All Things Open 2017: The Apache Software Foundation 101
ODP
The Apache Way
PPT
Keynote: Community, Code and Companies - Mark Hinkle, Director of Open Source...
PDF
Open Source Management
KEY
Creating community - The Apache Way
PDF
The History of The Apache Software Foundation
PDF
Open Source - Not just for IT anymore
PDF
Open Source at the Apache Software Foundation
PDF
State of the Feather - ApacheCon North America 2018
PDF
State of the Feather - Apache:Big Data - Budapest
ODP
The apacheway
PDF
Bending the Rules: Community over Code over Policy.
PDF
BNYMellon - CVE 101.pdf
PDF
JacksonvilleJUG_CVE101.pdf
Craig The apache Way
The Apache Way (And How Not to Break Builds!)
Security in the age of open source - Myths and misperceptions
Geecon 2017 Anatomy of Java Vulnerabilities
The Apache Way: A Proven Way Toward Success
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
All Things Open 2017: The Apache Software Foundation 101
The Apache Way
Keynote: Community, Code and Companies - Mark Hinkle, Director of Open Source...
Open Source Management
Creating community - The Apache Way
The History of The Apache Software Foundation
Open Source - Not just for IT anymore
Open Source at the Apache Software Foundation
State of the Feather - ApacheCon North America 2018
State of the Feather - Apache:Big Data - Budapest
The apacheway
Bending the Rules: Community over Code over Policy.
BNYMellon - CVE 101.pdf
JacksonvilleJUG_CVE101.pdf
Ad

More from Bertrand Delacretaz (20)

PDF
VanillaJS & the Web Platform, a match made in heaven?
PDF
Surviving large online communities with conciseness and clarity
PDF
Repoinit: a mini-language for content repository initialization
PDF
The Moving House Model, adhocracy and remote collaboration
PDF
GraphQL in Apache Sling - but isn't it the opposite of REST?
PDF
Open Source Changes the World!
PDF
How to convince your left brain (or manager) to follow the Open Source path t...
PDF
L'Open Source change le Monde - BlendWebMix 2019
PDF
Shared Neurons - the Secret Sauce of Open Source communities?
PDF
Sling and Serverless, Best Friends Forever?
PDF
Serverless - introduction et perspectives concrètes
PDF
Karate, the black belt of HTTP API testing?
PDF
Open Source at Scale: the Apache Software Foundation (2018)
PDF
They don't understand me! Tales from the multi-cultural trenches
PDF
Prise de Décisions Asynchrone, Devoxx France 2018 (avec vidéo)
PDF
La Fondation Apache - keynote au Paris Open Source Summit 2017
PDF
Building an Apache Sling Rendering Farm
PDF
Who needs meetings? Asynchronous Decision Making to the rescue
PDF
Simple software is hard...don't give up!
PDF
I will NOT attend your meeting - I'm an Open Source person
VanillaJS & the Web Platform, a match made in heaven?
Surviving large online communities with conciseness and clarity
Repoinit: a mini-language for content repository initialization
The Moving House Model, adhocracy and remote collaboration
GraphQL in Apache Sling - but isn't it the opposite of REST?
Open Source Changes the World!
How to convince your left brain (or manager) to follow the Open Source path t...
L'Open Source change le Monde - BlendWebMix 2019
Shared Neurons - the Secret Sauce of Open Source communities?
Sling and Serverless, Best Friends Forever?
Serverless - introduction et perspectives concrètes
Karate, the black belt of HTTP API testing?
Open Source at Scale: the Apache Software Foundation (2018)
They don't understand me! Tales from the multi-cultural trenches
Prise de Décisions Asynchrone, Devoxx France 2018 (avec vidéo)
La Fondation Apache - keynote au Paris Open Source Summit 2017
Building an Apache Sling Rendering Farm
Who needs meetings? Asynchronous Decision Making to the rescue
Simple software is hard...don't give up!
I will NOT attend your meeting - I'm an Open Source person
Ad

Recently uploaded (20)

PDF
System and Network Administration Chapter 2
PPTX
ISO 45001 Occupational Health and Safety Management System
PPTX
history of c programming in notes for students .pptx
PPTX
Odoo POS Development Services by CandidRoot Solutions
PPTX
Online Work Permit System for Fast Permit Processing
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Introduction to Artificial Intelligence
PPTX
ai tools demonstartion for schools and inter college
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PDF
AI in Product Development-omnex systems
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PPTX
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
System and Network Administration Chapter 2
ISO 45001 Occupational Health and Safety Management System
history of c programming in notes for students .pptx
Odoo POS Development Services by CandidRoot Solutions
Online Work Permit System for Fast Permit Processing
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Introduction to Artificial Intelligence
ai tools demonstartion for schools and inter college
Understanding Forklifts - TECH EHS Solution
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Navsoft: AI-Powered Business Solutions & Custom Software Development
Which alternative to Crystal Reports is best for small or large businesses.pdf
Wondershare Filmora 15 Crack With Activation Key [2025
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Upgrade and Innovation Strategies for SAP ERP Customers
AI in Product Development-omnex systems
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
How to Choose the Right IT Partner for Your Business in Malaysia

Project and Community Services the Apache Way

  • 1. Project + Community Services The Apache Way slides revision: 2017-12-06 - photos: Adobe Stock, unless otherwise specified Emmanuel Lécharny - @elecharny_tek
 Apache Software Foundation Member
 Software Architect, Symas Bertrand Delacrétaz - @bdelacretaz
 Member of the Board of Directors, Apache Software Foundation
 Principal Scientist, Adobe Research Switzerland Paris Open Source Summit 2017 - Community Summit
  • 3. The ASF’s Mission The Apache Software Foundation (ASF) is a 
 US 501(c)(3) charitable organization.
 Its mission is to provide Open Source software for the public good. 
 We do this by providing services and support for many like-minded software project communities of individuals who choose to join the ASF. https://www.apache.org/foundation/ A neutral space in which projects which are independent from any corporate influence can prosper and create Open Source software for the public good. Under the business-friendly
 Apache License 2.0 photos: http://archive.apachecon.com/c/
  • 4. About 300 top-level projects, 50 in incubation and 40 in attic.apache.org
 Clean retirement is part of the ASF project’s lifecycle
  • 5. Which parts of the value chain? Documentation
 Marketing
 Packaging Configuration
 Helpdesk
 Operations source code product system Architecture Development Tests unitaires Write source code, distribute and document it…that’s all.
  • 13. Value chain? source code product system Write source code, distribute and document it…
 that’s all. The ASF’s services are primarily meant for its projects and developers - users will need some assembly.
  • 15. -------- Forwarded Message --------
 Subject: Command Injection through LDAP CSV export
 Date: Mon, 30 Nov 2015 00:12:52 +0500
 From: xxx@gmail.com>
 To: security@apache.org
 
 Hello there Apache team,
 
 This is Whitehat and i would like to report a command injection vulnerability in
 the Apache <project> CSV export feature described in
 https://<project>.apache.org/<project>users-guide/tools_csvexport_wizard.html
 
 The "CSV export" feature of Apache Activity records that sends out does not properly 
 "escape" fields. This allows malicious users to turn the editable fields into active content 
 so when that when users downloads the ticket data csv and opens it,
 the active content gets executed. 
 
 Mitigation
 Ensure all fields are properly "escaped" before returning the CSV file to the user. ALARM 
 all hands on deck!
  • 16. Dear Apache <project> PMC,
 
 The attached security vulnerability report has been received
 by the Apache Security Team and is being passed to you
 for action.
 
 Please take careful note of the following:
 - This information is private and should be treated accordingly. The
 issue must not be discussed on a public mailing list, it must not
 be added to a public bug tracker, etc.
 - The <project> PMC is responsible for resolving this issue. The
 security team is here to provide help and advice but the
 responsibility to do the work lies with the <project> PMC.
 
 You may find the "ASF Project Security for Committers" [1] a useful
 reference. This e-mail represents step 3 of that process. 
 Step 4 should be completed asap.
 
 Kind regards,
 Mark, for the Apache Security Team
 [1] http://www.apache.org/security/committers.html security@ apache
 -> project
  • 18. Due diligence: your business - your responsibility ! Don’t blame OSS for not doing your job…
 Read the OSS “fine print”…
 Don’t you love those
 security reports? “12. DISCLAIMER OF WARRANTY.
 The software is licensed “as-is.” You bear the risk of using it. XXX gives
 no express warranties, guarantees or conditions.”
 (where XXX is a closed source vendor…)