Re: [ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread Gokul Raj
Should we update dependancy jar or is that okay to update only struts core jar? On Wed, 22 Aug 2018 at 13:05, Yasser Zamani wrote: > The Apache Struts group is pleased to announce that Struts 2.3.35 is > available as a “General Availability” release. The GA designation is > our highest quality g

RE: [ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread FAGES, Amaury
Hi, Indeed, mea culpa. We often look at https://mvnrepository.com and always though itw as mirror but apparently not. Build is OK and releases pending. Thank you again. Amaury Fages Aspiring Architect |  Center Capgemini Fran

Re: [ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread Yasser Zamani
Hi there, thank you for posting, As far as I see, it should be already available. For example see [1]. What is the repository URL you wish see Struts 2.3.35 there, please? Regards. [1] http://repo1.maven.org/maven2/org/apache/struts/struts2-core/2.3.35/ On 8/22/2018 6:37 PM, FAGES, Amaury wrot

RE: [ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread FAGES, Amaury
Hi Struts team, thank you. We are currently upgrading our flawed apps. Some are 2.3.x, any ETA on 2.3.35 availability through Maven Central or we are forced for now to add dependency manually on inner repository ? Thank you.

Re: [ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread Yasser Zamani
On 8/22/2018 4:19 PM, Martin Gainty wrote: > Yasser > > which CVE or group of CVEs does this address? Thanks for your posting Martin, This addresses CVE-2018-11776 as I mentioned in it's S2-057's link and announced into user list at [1]. Regards. [1] https://lists.apache.org/thread.html/75981

Re: [ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread Martin Gainty
Yasser which CVE or group of CVEs does this address? From: Yasser Zamani on behalf of Yasser Zamani Sent: Wednesday, August 22, 2018 3:35 AM To: Struts User; Struts Announcements; Apache Announce Subject: [ANN] Apache Struts 2.3.35 GA with Security Fixes Releas

RE: Is HttpParameters Supposed to be Immutable

2018-08-22 Thread Paul Zepernick
Thanks for the feedback. I will open up a bug and submit a PR 😊 Paul -Original Message- From: Lukasz Lenart Sent: Wednesday, August 22, 2018 12:54 AM To: Struts Users Mailing List Subject: Re: Is HttpParameters Supposed to be Immutable wt., 21 sie 2018 o 18:32 Paul Zepernick napisał(

[ANN] CVE-2018-11776 Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16

2018-08-22 Thread Yasser Zamani
[CVEID]:CVE-2018-11776 [PRODUCT]:Apache Struts [VERSION]:Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16 [PROBLEMTYPE]:Remote Code Execution [REFERENCES]:https://cwiki.apache.org/confluence/display/WW/S2-057 [DESCRIPTION]:Man Yue Mo from the Semmle Security Research team was noticed that Apache Strut

[ANN] Apache Struts 2.5.17 GA with Security Fixes Release

2018-08-22 Thread Yasser Zamani
The Apache Struts group is pleased to announce that Struts 2.5.17 is available as a “General Availability” release. The GA designation is our highest quality grade. In addition to critical overall proactive security improvements, this release addresses one potential security vulnerability: - Possi

[ANN] Apache Struts 2.3.35 GA with Security Fixes Release

2018-08-22 Thread Yasser Zamani
The Apache Struts group is pleased to announce that Struts 2.3.35 is available as a “General Availability” release. The GA designation is our highest quality grade. In addition to critical overall proactive security improvements, this release addresses one potential security vulnerability: - Possi