Bug#553644:

2009-12-15 Thread Pablo Duboue
fixed 553644 6.1.22 thanks (resending as I forgot to CC: the BTS) We don't ship the test WebApps enabled by default (from what I can gather, it seems we don't ship them at all) and this new version fixes the remaining XSS vulnerabilities (I double checked the fix is in). This bug will be closed

Bug#553644:

2009-12-15 Thread Pablo Duboue
fixed 6.1.22 thanks We don't ship the test WebApps enabled by default (from what I can gather, it seems we don't ship them at all) and this new version fixes the remaining XSS vulnerabilities (I double checked the fix is in). This bug will be closed when the new version gets uploaded. -- To U

Bug#553644: jetty: multiple vulnerabilities

2009-11-01 Thread Raphael Geissert
Source: jetty Severity: grave Tags: security Hi, Multiple vulnerabilities have been discovered in jetty 6.x and 7.x. The original advisory can be found at http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt When you fix this issue, please mention the CVE ids in the changelog, if they are