Subsonic security issue
I have installed the evaluation version of Subsonic and I am very impressed with the work that went into its design! We are eager to "donate" and register the program but there is an grave issue the must be addressed:
Subsonic currently uses version 6 of the Jetty server. This version has well known and very dangerous security problems which have been corrected in version 9 (and I believe in version 8 as well).
Sadly, since our computer is a business computer, it must meet PCI compliance. The use of Jetty 6 is an automatic failure (which demonstrates how insecure version 6 really is), so without the upgrade in Jetty subsonic is rendered useless to us. Jetty 6 or below is prohibited due to the security holes.
Would someone explain how to upgrade the Jetty server in version 4.7 of subsonic running on Windows 7 64 bit platform? Or is an upgraded version currently in the works?
Please advise
Thank you
Subsonic currently uses version 6 of the Jetty server. This version has well known and very dangerous security problems which have been corrected in version 9 (and I believe in version 8 as well).
Sadly, since our computer is a business computer, it must meet PCI compliance. The use of Jetty 6 is an automatic failure (which demonstrates how insecure version 6 really is), so without the upgrade in Jetty subsonic is rendered useless to us. Jetty 6 or below is prohibited due to the security holes.
Would someone explain how to upgrade the Jetty server in version 4.7 of subsonic running on Windows 7 64 bit platform? Or is an upgraded version currently in the works?
Please advise
Thank you