Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-04 Thread Rene Gielen
Just browsing the results of a search to "xss severity" on Google, at a first glance most people seem to rate XSS exploits as "high", which would map to "Important" in MS speech. Am Di, 4.03.2008, 10:39, schrieb Don Brown: > Well, this was the first hit on google: > http://www.microsoft.com/techne

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-04 Thread Rene Gielen
ECTED]> > To: "Struts Developers List" > Sent: Tuesday, March 04, 2008 8:04 AM > Subject: Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED > ANNOUNCEMENT > > >> What about: >> >> * All developers are strongly advised to update Struts 2 applic

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-04 Thread Don Brown
Well, this was the first hit on google: http://www.microsoft.com/technet/security/bulletin/rating.mspx Therefore, I'd say Moderate to Important. Don On 3/4/08, Rene Gielen <[EMAIL PROTECTED]> wrote: > Yes, sounds good to me. How about the criticality rating in the > bulletin? "Critical" was - I

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-04 Thread Al Sutton
esday, March 04, 2008 8:04 AM Subject: Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT What about: * All developers are strongly advised to update Struts 2 applications to Struts 2.0.11.1 to prevent XSS attacks through Struts 2 tags. In this way, we aren't quit

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-04 Thread Rene Gielen
Yes, sounds good to me. How about the criticality rating in the bulletin? "Critical" was - I have to admit :) - just copied from 001, what would be a fitting rating here? Don Brown schrieb: > What about: > > * All developers are strongly advised to update Struts 2 applications > to Struts 2.0.11.

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-04 Thread Don Brown
What about: * All developers are strongly advised to update Struts 2 applications to Struts 2.0.11.1 to prevent XSS attacks through Struts 2 tags. In this way, we aren't quite so "in-your-face" and a quick summary of the issue and what part of Struts 2 is affected is included. The qualifier is p

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Rene Gielen
Agreed. How should we put it better? Don Brown schrieb: > Good point. This pales in comparison to, say, the OGNL remote code > exploit. XSS exploits, while important, just aren't anywhere near as > big of deal. > > Don > > On Tue, Mar 4, 2008 at 12:43 PM, Jeromy Evans > <[EMAIL PROTECTED]> wro

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Don Brown
Good point. This pales in comparison to, say, the OGNL remote code exploit. XSS exploits, while important, just aren't anywhere near as big of deal. Don On Tue, Mar 4, 2008 at 12:43 PM, Jeromy Evans <[EMAIL PROTECTED]> wrote: > My opinion is that the criticality is overstated. > However it is

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Jeromy Evans
My opinion is that the criticality is overstated. However it is useful to draw attention to the vulnerability. Don Brown wrote: Looks good. Thanks for creating a security bulletin as well. Don On 3/4/08, Rene Gielen <[EMAIL PROTECTED]> wrote: The release has been submitted for mirroring.

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Rene Gielen
Good point. How about ALL DEVELOPERS USING STRUTS 2 ARE STRONGLY ADVISED TO UPDATE TO STRUTS 2.0.11.1 IMMEDIATELY! Wendy Smoak schrieb: > On Mon, Mar 3, 2008 at 6:24 PM, Rene Gielen <[EMAIL PROTECTED]> wrote: >> The release has been submitted for mirroring. Here's a draft >> announcement that we

Re: [struts-dev] [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Dale Newfield
Wendy Smoak wrote: * ALL DEVELOPERS ARE STRONGLY ADVISED TO UPDATE TO STRUTS 2.0.11.1 IMMEDIATELY! All developers using Struts 2 are ... ? I think we need to make it clear that Struts 1 apps are not affected. That's true, but since there may be people that see this notice and then update

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Wendy Smoak
On Mon, Mar 3, 2008 at 6:24 PM, Rene Gielen <[EMAIL PROTECTED]> wrote: > The release has been submitted for mirroring. Here's a draft > announcement that we could post tomorrow morning, including a link to a > corresponding security bulletin announcement in the wiki. Comments and > corrections t

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Don Brown
Looks good. Thanks for creating a security bulletin as well. Don On 3/4/08, Rene Gielen <[EMAIL PROTECTED]> wrote: > The release has been submitted for mirroring. Here's a draft > announcement that we could post tomorrow morning, including a link to a > corresponding security bulletin announce

Re: [VOTE] Struts 2.0.11.1 Quality (fast track) - PROPOSED ANNOUNCEMENT

2008-03-03 Thread Rene Gielen
The release has been submitted for mirroring. Here's a draft announcement that we could post tomorrow morning, including a link to a corresponding security bulletin announcement in the wiki. Comments and corrections to both texts are highly appreciated. Apache Struts 2.0.11.1 is now availabl