Re: Is there a future 2.3.x release for CVE-2018-7489 recently

2018-03-30 Thread Lukasz Lenart
2018-03-30 12:39 GMT+02:00 song6...@gmail.com : > Hi Lukasz, > Sorry I paste the wrong CVE identifier in subject, the CVE I want to check is > CVE-2018-1327(S2-056, Affected Software, Struts 2.1.1 - Struts 2.5.14.1). > > Actually, my application don't even have Struts REST plugin jars in it's > p

Re: Is there a future 2.3.x release for CVE-2018-7489 recently

2018-03-30 Thread song6295
Hi Lukasz, Sorry I paste the wrong CVE identifier in subject, the CVE I want to check is CVE-2018-1327(S2-056, Affected Software, Struts 2.1.1 - Struts 2.5.14.1). Actually, my application don't even have Struts REST plugin jars in it's package. But seems one of my big customer have very strict

Re: Is there a future 2.3.x release for CVE-2018-7489 recently

2018-03-30 Thread Lukasz Lenart
2018-03-30 5:14 GMT+02:00 song6...@gmail.com : > My team need to fix CVE-2018-7489 in few days and there's lots code changes > if we migrate to 2.5.x. > Where I can find the release schedule plans for struts2? Not sure what do you mean by that? This vulnerability is only possible to happen when y

Is there a future 2.3.x release for CVE-2018-7489 recently

2018-03-30 Thread song6295
My team need to fix CVE-2018-7489 in few days and there's lots code changes if we migrate to 2.5.x. Where I can find the release schedule plans for struts2? Thanks. - To unsubscribe, e-mail: user-unsubscr...@struts.apache.org F