[jira] [Commented] (TRINIDAD-2542) CVE-2016-5019: MyFaces Trinidad view state deserialization security vulnerability

2016-09-29 Thread Mike Kienenberger (JIRA)
[ https://issues.apache.org/jira/browse/TRINIDAD-2542?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15533282#comment-15533282 ] Mike Kienenberger commented on TRINIDAD-2542: - The "information disclosure vulnerability"

[jira] [Commented] (TRINIDAD-2542) CVE-2016-5019: MyFaces Trinidad view state deserialization security vulnerability

2016-09-29 Thread Brian Martin (JIRA)
[ https://issues.apache.org/jira/browse/TRINIDAD-2542?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15533270#comment-15533270 ] Brian Martin commented on TRINIDAD-2542: Generally, deserialization attacks lead to remote code

[jira] [Commented] (TRINIDAD-2542) CVE-2016-5019: MyFaces Trinidad view state deserialization security vulnerability

2016-09-29 Thread Mike Kienenberger (JIRA)
[ https://issues.apache.org/jira/browse/TRINIDAD-2542?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15533170#comment-15533170 ] Mike Kienenberger commented on TRINIDAD-2542: - All users of Apache Trinidad should upgrade