Security Bulletin: SWF Vulnerability in YUI 2
An external source has notified us of a previously unknown security vulnerability in YUI 2 involving hosted
This problem is not reproducible in YUI 3.
If you are using or even merely hosting any YUI 2
.swf file, please take steps to remove these files immediately from your hosts.
YUI 2 is an end-of-lifed project and is no longer supported. All YUI 2
.swf files have been removed from the Yahoo CDN. If your site was taking advantage of the presence of these files on the Yahoo CDN they will no longer be available.
We recommend projects remove all Flash-based features unless they are prepared to devote proper resources and attention to addressing security issues.
Note that all Flash files have been already deprecated and removed from YUI 3. If you must use these features, you will need to compile and host your own
.swf files using source from the yui3-swfs repo.
These details have been captured as well in a YUI Security Bulletin for future reference.
A big thank you to @soiaxx who reported this to us.