Cloud provider Atlassian has moved to patch what a security researcher describes as a backdoor in its enterprise single sign-on Crowd service. However, the company is disputing Command Five's assertion that a second, as-yet-unpatched vulnerability remains. Command Five's advisory states that XML DTD (document type definition) …
The first time through I read that as "Alsatian", and thought, wow, most people are happy enough to get their dogs to fetch...
Atlassian plugging the backdoor
I'd prefer to hear about Atlassian plugging the backdoor.
Any word on why they didn't fix this vulnerability a year ago when it was first reported to them?
- It's true, the START MENU is coming BACK to Windows 8, hiss sources
- Pic NASA Mars tank Curiosity rolls on old WET PATCH, sighs, sniffs for life signs
- How UK air traffic control system was caught asleep on the job
- Google embiggens its fat vid pipe Chromecast with TEN new supported apps
- Microsoft: Don't listen to 4chan ... especially the bit about bricking Xbox Ones