Apache Roller 5.0.1 available & upgrade recommended for all Roller sites

Dave <[email protected]>
Newsgroups gmane.comp.java.roller.user
Message-ID <CAF1aazDr5UqZakTrPLTUhQRj0ZGg_kv8NyLaQgs37wKzk8wTbQ__38134.1758104556$1340557435$gmane$org@mail.gmail.com>
New release: Apache Roller 5.0.1 is now available on Apache mirrors
world-wide and you can find it here:

   http://roller.apache.org/downloads.html

This release fixes two security vulnerabilities in Roller, listed below:
   CVE-2012-2380: Apache Roller Cross-Site-Resource-Forgery (XSRF) vulnerability
   CVE-2012-2381: Apache Roller Cross-Site-Scripting (XSS) vulnerability

Because the above are serious security vulnerabilities, we recommend
that all sites running Apache Roller upgrade to this new release as
soon as possible.

Thanks,
Dave


-- 
Dave M. Johnson
Apache Roller PMC Chair
http://rollerweblogger.org/roller
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.