Fwd: [SECURITY] Frame injection vulnerability in published Javadoc

2013-06-24 Thread Jean-Baptiste Onofré
Hi all, I guess that most of you already saw this warning e-mail. Camel, ActiveMQ, and CXF are affected (Karaf is not). I will start to review ActiveMQ today and Camel tomorrow. Is someone from CXF can take a quick look ? I will get back to you soon for ActiveMQ and Camel. Thanks ! Regards

Fwd: [SECURITY] Frame injection vulnerability in published Javadoc

2013-06-24 Thread Charles Moulliard
FYI -- Forwarded message -- From: Mark Thomas ma...@apache.org Date: Thu, Jun 20, 2013 at 10:29 AM Subject: [SECURITY] Frame injection vulnerability in published Javadoc To: committ...@apache.org Cc: r...@apache.org Hi All, Oracle has announced [1], [2] a frame injection

Re: Fwd: [SECURITY] Frame injection vulnerability in published Javadoc

2013-06-24 Thread Jean-Baptiste Onofré
FYI, already addressed this morning ;) On 06/24/2013 12:57 PM, Charles Moulliard wrote: FYI -- Forwarded message -- From: Mark Thomas ma...@apache.org Date: Thu, Jun 20, 2013 at 10:29 AM Subject: [SECURITY] Frame injection vulnerability in published Javadoc To: