users@glassfish.java.net

Cross-Site Scripting (XSS) Vulnerabilities in Sun GlassFish Enterprise Server May Allow Execution of JavaScript Code

From: Derek Sceats <dsceats_at_silasg.com>
Date: Thu, 28 May 2009 15:22:58 -0700

Hi All,
 
I noticed that there is a security alert regarding Glassfish v2.1, and a solution for Sun customers with a valide support contract...
http://sunsolve.sun.com/search/document.do?assetkey=1-66-258528-1
 
I have only recently joined the Glassfish user group and was unable to find record of this issue. How will this issue be resolved for the open source community without a Sun support contract?
 
Thanks in advance.
 
Regards,
Derek Sceats