<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: Link: Spring-MVC Cross-Site Scripting Vulnerabilities</title>
	<atom:link href="http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/</link>
	<description>Johannes Brodwall&#039;s Musings on Software Architecture and Programming</description>
	<lastBuildDate>Thu, 29 Jul 2010 15:37:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Kukenspeil</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-2860</link>
		<dc:creator>Kukenspeil</dc:creator>
		<pubDate>Fri, 09 Mar 2007 19:33:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-2860</guid>
		<description>&quot;I have a dream that one day the Spring Framework will add &quot;secure by
default&quot; to its list of fundamental design principles.&quot;

Well if that happened, then Sverre could well be out of a lot of consulting revenue!</description>
		<content:encoded><![CDATA[<p>&#8220;I have a dream that one day the Spring Framework will add &#8220;secure by<br />
default&#8221; to its list of fundamental design principles.&#8221;</p>
<p>Well if that happened, then Sverre could well be out of a lot of consulting revenue!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kukenspeil</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-84965</link>
		<dc:creator>Kukenspeil</dc:creator>
		<pubDate>Fri, 09 Mar 2007 16:33:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-84965</guid>
		<description>&quot;I have a dream that one day the Spring Framework will add &quot;secure by&lt;br&gt;default&quot; to its list of fundamental design principles.&quot;&lt;br&gt;&lt;br&gt;Well if that happened, then Sverre could well be out of a lot of consulting revenue!</description>
		<content:encoded><![CDATA[<p>&#8220;I have a dream that one day the Spring Framework will add &#8220;secure by<br />default&#8221; to its list of fundamental design principles.&#8221;</p>
<p>Well if that happened, then Sverre could well be out of a lot of consulting revenue!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sverre</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-2644</link>
		<dc:creator>Sverre</dc:creator>
		<pubDate>Wed, 07 Mar 2007 23:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-2644</guid>
		<description>Jeez, guys, let&#039;s be friends. After all, it&#039;s just bits and bytes.

And I&#039;ve been informed that the only _bug_ I point at is being fixed in the next 2.0.x release. Not because of me, but because someone reported it the day after I started mailing my thoughts to some friends.

The design flaw may be (maybe) addressed in the next 2.x.y release.</description>
		<content:encoded><![CDATA[<p>Jeez, guys, let&#8217;s be friends. After all, it&#8217;s just bits and bytes.</p>
<p>And I&#8217;ve been informed that the only _bug_ I point at is being fixed in the next 2.0.x release. Not because of me, but because someone reported it the day after I started mailing my thoughts to some friends.</p>
<p>The design flaw may be (maybe) addressed in the next 2.x.y release.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sverre</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-84964</link>
		<dc:creator>Sverre</dc:creator>
		<pubDate>Wed, 07 Mar 2007 20:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-84964</guid>
		<description>Jeez, guys, let&#039;s be friends. After all, it&#039;s just bits and bytes.&lt;br&gt;&lt;br&gt;And I&#039;ve been informed that the only _bug_ I point at is being fixed in the next 2.0.x release. Not because of me, but because someone reported it the day after I started mailing my thoughts to some friends.&lt;br&gt;&lt;br&gt;The design flaw may be (maybe) addressed in the next 2.x.y release.</description>
		<content:encoded><![CDATA[<p>Jeez, guys, let&#39;s be friends. After all, it&#39;s just bits and bytes.</p>
<p>And I&#39;ve been informed that the only _bug_ I point at is being fixed in the next 2.0.x release. Not because of me, but because someone reported it the day after I started mailing my thoughts to some friends.</p>
<p>The design flaw may be (maybe) addressed in the next 2.x.y release.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johannes Brodwall</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-2630</link>
		<dc:creator>Johannes Brodwall</dc:creator>
		<pubDate>Wed, 07 Mar 2007 16:33:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-2630</guid>
		<description>Hi, Anders. If this was a bona-fide bug, I&#039;d agree with you. It&#039;s a request to &quot;default to safe&quot;, which is something different. In this case, the onus to fix is on the billions of software developers using Spring-MVC. But the Spring team could ease their pain. (And I&#039;m not going to be drawn into a discussion about the bestitude of Sverre)</description>
		<content:encoded><![CDATA[<p>Hi, Anders. If this was a bona-fide bug, I&#8217;d agree with you. It&#8217;s a request to &#8220;default to safe&#8221;, which is something different. In this case, the onus to fix is on the billions of software developers using Spring-MVC. But the Spring team could ease their pain. (And I&#8217;m not going to be drawn into a discussion about the bestitude of Sverre)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr. Senseless Talker</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-2629</link>
		<dc:creator>Mr. Senseless Talker</dc:creator>
		<pubDate>Wed, 07 Mar 2007 16:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-2629</guid>
		<description>I&#039;m glad you have trust in Sverre (he&#039;s the best), but I know for a fact it has yet to be reported. The issue here is timing. Giving the maintainer of the affected product some time to respond to the issue before disclosing the advisory is common practise among most sane people. For future reference; see http://www.wiretrip.net/rfp/policy.html for an excellent guideline for handling the interaction between a security researchers and software maintainers. Given the fact that Spring-MVC is being widely used among financial applications, I&#039;m left to hope that the readers of your blog are merely people with good intentions. Hopefully we&#039;ll all be able to fetch Spring-MVC 2.0.3 from our local mirror very soon.</description>
		<content:encoded><![CDATA[<p>I&#8217;m glad you have trust in Sverre (he&#8217;s the best), but I know for a fact it has yet to be reported. The issue here is timing. Giving the maintainer of the affected product some time to respond to the issue before disclosing the advisory is common practise among most sane people. For future reference; see <a href="http://www.wiretrip.net/rfp/policy.html" rel="nofollow">http://www.wiretrip.net/rfp/policy.html</a> for an excellent guideline for handling the interaction between a security researchers and software maintainers. Given the fact that Spring-MVC is being widely used among financial applications, I&#8217;m left to hope that the readers of your blog are merely people with good intentions. Hopefully we&#8217;ll all be able to fetch Spring-MVC 2.0.3 from our local mirror very soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johannes Brodwall</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-2627</link>
		<dc:creator>Johannes Brodwall</dc:creator>
		<pubDate>Wed, 07 Mar 2007 14:15:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-2627</guid>
		<description>Poppycock, Anders :-). A security advisory with a workaround should always be welcome. Security is always better when information is widely disseminated.

But the issue should be reported to the Spring team *as well*. And I trust Sverre is one step ahead of us on this.</description>
		<content:encoded><![CDATA[<p>Poppycock, Anders :-). A security advisory with a workaround should always be welcome. Security is always better when information is widely disseminated.</p>
<p>But the issue should be reported to the Spring team *as well*. And I trust Sverre is one step ahead of us on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anders Furseth</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-2625</link>
		<dc:creator>Anders Furseth</dc:creator>
		<pubDate>Wed, 07 Mar 2007 13:54:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-2625</guid>
		<description>As interesting as this is, Sverre has yet to report the issues to the Spring-MVC team, making this premature disclosure unethical at best.</description>
		<content:encoded><![CDATA[<p>As interesting as this is, Sverre has yet to report the issues to the Spring-MVC team, making this premature disclosure unethical at best.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johannes Brodwall</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-84963</link>
		<dc:creator>Johannes Brodwall</dc:creator>
		<pubDate>Wed, 07 Mar 2007 13:33:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-84963</guid>
		<description>Hi, Anders. If this was a bona-fide bug, I&#039;d agree with you. It&#039;s a request to &quot;default to safe&quot;, which is something different. In this case, the onus to fix is on the billions of software developers using Spring-MVC. But the Spring team could ease their pain. (And I&#039;m not going to be drawn into a discussion about the bestitude of Sverre)</description>
		<content:encoded><![CDATA[<p>Hi, Anders. If this was a bona-fide bug, I&#39;d agree with you. It&#39;s a request to &#8220;default to safe&#8221;, which is something different. In this case, the onus to fix is on the billions of software developers using Spring-MVC. But the Spring team could ease their pain. (And I&#39;m not going to be drawn into a discussion about the bestitude of Sverre)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr. Senseless Talker</title>
		<link>http://johannesbrodwall.com/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/comment-page-1/#comment-84962</link>
		<dc:creator>Mr. Senseless Talker</dc:creator>
		<pubDate>Wed, 07 Mar 2007 13:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.brodwall.com/johannes/blog/2007/03/06/link-spring-mvc-cross-site-scripting-vulnerabilities/#comment-84962</guid>
		<description>I&#039;m glad you have trust in Sverre (he&#039;s the best), but I know for a fact it has yet to be reported. The issue here is timing. Giving the maintainer of the affected product some time to respond to the issue before disclosing the advisory is common practise among most sane people. For future reference; see &lt;a href=&quot;http://www.wiretrip.net/rfp/policy.html&quot;&gt;http://www.wiretrip.net/rfp/policy.html&lt;/a&gt; for an excellent guideline for handling the interaction between a security researchers and software maintainers. Given the fact that Spring-MVC is being widely used among financial applications, I&#039;m left to hope that the readers of your blog are merely people with good intentions. Hopefully we&#039;ll all be able to fetch Spring-MVC 2.0.3 from our local mirror very soon.</description>
		<content:encoded><![CDATA[<p>I&#39;m glad you have trust in Sverre (he&#39;s the best), but I know for a fact it has yet to be reported. The issue here is timing. Giving the maintainer of the affected product some time to respond to the issue before disclosing the advisory is common practise among most sane people. For future reference; see <a href="http://www.wiretrip.net/rfp/policy.html">http://www.wiretrip.net/rfp/policy.html</a> for an excellent guideline for handling the interaction between a security researchers and software maintainers. Given the fact that Spring-MVC is being widely used among financial applications, I&#39;m left to hope that the readers of your blog are merely people with good intentions. Hopefully we&#39;ll all be able to fetch Spring-MVC 2.0.3 from our local mirror very soon.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
