Today I moved this issue from HUDSON- into SECURITY project:
http://issues.hudson-ci.org/browse/SECURITY-5
..and committed these changes:
http://hudson-ci.org/commit/33626
Kohsuke, I recommend a release with these changes ASAP.
Thanks,
- Alan