Project Roller
Blogs, news and views
Roller is the open source Java blog server that drives blogs.sun.com, blog.usa.gov, IBM Lotus Connections, IBM Developer Works blogs and numerous others. Read more on the about page.
Quick Links
Navigation
Apache Roller 5.0.1 security fix release now available
06.24.2012 | 0 Comments
All Roller sites are urged to upgrade to Roller 5.0.1 as soon as possible. Download Apache Roller 5.0.1 at the Roller downloads page here:
http://roller.apache.org/downloads.cgi
The two security vulnerabilities have been reported to the Full Disclosure mailing-list at grok.org.uk
and the Bugtraq list at SecurityFocus.com
. You can find a little more information about the vulnerabilities at the links below:
- CVE-2012-2380: Roller Cross-Site-Resource-Forgery (XSRF) vulnerability
- CVE-2012-2381: Roller Cross-Site-Scripting (XSS) vulnerability


