Struts zero-day vulnerability

2014-05-05 Thread Deepak Subbanarasimha
Hello, We use struts version 1.2.2 and commons-file upload version 1.1.1. It is not clear from this notification if these versions are impacted. 1. Can anyone confirm if these versions or affected? 2. If they are affected, what can be done? Should we upgrade to Struts 2.x? The n

RE: Struts zero-day vulnerability

2014-05-16 Thread Deepak Subbanarasimha
migration to Struts2 or any other modern framework. [1] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Protect-your-Struts1-applications/ba-p/6463188#.U2d8va2wlzt [2] http://struts.apache.org/struts1eol-announcement.html 2014-05-05 13:53 GMT+02:00 Deepak Subbanarasimha : > Hello, >