dev@javaserverfaces.java.net

Re: JSF security issue

From: Ed Burns <edward.burns_at_oracle.com>
Date: Thu, 10 Jun 2010 12:30:35 -0700

>>>>> On Wed, 09 Jun 2010 08:38:43 -0400, Stan Silvert <ssilvert_at_redhat.com> said:

SS> I haven't analyzed this, but wanted to make sure everyone was aware:
SS> http://www.theregister.co.uk/2010/06/08/padding_oracle_attack_tool/

We have been aware of this and have been acting on it since before its
public announcement.

Roger is the point man on this issue.

Ed

-- 
| edburns_at_oracle.com | office: +1 407 458 0017
| homepage:          | http://ridingthecrest.com/
| 21 Work Days Til JSF 2.1 Milestone 1