Re: Fix security vulnerability

2014-07-09 Thread Ruchika Mahajan
Hi, CVE-2014-0114 was present till 1.3.10 version. In https://issues.apache.org/jira/browse/STR/?selectedTab=com.atlassian.jira.jira-projects-plugin:roadmap-panel link there are releases for 1.x after 1.3.10. So just wanted to confirm, is CVE-2014-0114 fixed in any of the later releases of 1.3.10

CVE-2014-0114 in Struts-1.2.9.jar

2014-06-23 Thread Ruchika Mahajan
Hi, I have used struts-1.2.9.jar in a project. I found *CVE-2014-0114* vulnerability in this jar. While looking for the possible solutions for these I found that Struts 1.x has had its End-Of-Life announcement one year ago but it is looking for a correction/mitigation for this issue. Below is the