http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17
is version 4.1.9 affected? you say 'All versions of Confluence up to and including 4.1.7 are affected by this vulnerability'. but state that the fix for 4.1 is in 4.1.10.
thanks,
"It has been discovered that 4.1.9 contains an incomplete fix and is still vulnerable to a small subset of the issues above. Namely, a logged in administrator is still able to use the Denial of Service exploit. This is a very small risk in most environments and you may be able to treat 4.1.9 as not affected."
The advisory text is now updated.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.