fyi: http://forums.atlassian.com/thread.jspa?messageID=257307449&tstart=0#257307449
the announcements mentions that the fixes will be available in
confluence 3.0. I wonder if that means that they won't be backported
to 2.10.x. If that's the case then we'll be in a awkward position -
can't upgrade due to a major .0 release and can't stay on 2.10.x
because it's insecure.
I guess we'll have to wait and see, unless anyone from atlassian cares
to comment on this :-(
/i
PS: I wasn't able to do much with confluence 3.0 due to a crazy
workload related to JavaOne, but I expect that conf 3.0 will become a
priority for us when J1 is over.