Re: How long is Struts2 2.3.x expected to be supported?

2017-03-08 Thread Lukasz Lenart
2017-03-08 20:23 GMT+01:00 Jason D. Burkert : > Hello, > > How long is Struts2 2.3.x expected to be supported? > Months? Years? Foreseeable future? No exact plans but rather months and only in case of security fixes (and it also depends if something can be fixed or if a large refactoring is need

ognl exploit

2017-03-08 Thread Jim Spellman
Is there a way to turn off ognl, so to prevent this exploit? https://github.com/rapid7/metasploit-framework/issues/8064 I found someone trying to break into my server and was able to issue system level commands by injecting this ognl language into the content header of a multipart form. I'm curre

Re: ognl exploit

2017-03-08 Thread Jim Spellman
Ah looks like all I need to do is upgrade. I missed the release note on this... Jim On Wed, Mar 8, 2017 at 5:04 PM, Jim Spellman wrote: > Is there a way to turn off ognl, so to prevent this exploit? > https://github.com/rapid7/metasploit-framework/issues/8064 > > I found someone trying to break

How long is Struts2 2.3.x expected to be supported?

2017-03-08 Thread Jason D. Burkert
Hello, How long is Struts2 2.3.x expected to be supported? Months? Years? Foreseeable future? i.e. When MUST I migrate to 2.5.x? Thanks. -Jason - To unsubscribe, e-mail: user-unsubscr...@struts.apache.org For additional com

[ANN] Apache Struts 2.5.10.1 GA with Security Fixe Release

2017-03-08 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.10.1 is available as a “General Availability” release. The GA designation is our highest quality grade. This release addresses one potential security vulnerability: - Possible Remote Code Execution when performing file upload based on