Comment 11 for bug 914628

Revision history for this message
Kohsuke Kawaguchi (kk-kohsuke) wrote :

Hi, Steve,

Upstream maintainer here. The fix is in line with what's done in Tomcat and other application servers that are affected by the same vulnerability, so I believe this is an accepted practice.