-1

I just read about this new struts2 security problem. I want to tell our developers to patch it, but I wish for some more sources first. The only source he cites is in another language. I guess I could spend the better part of the day testing it, but if I could get confirmation from other sources, it would be better. The blog author claims to have discussed it with the Struts security team. How can I get confirmation from them that this is indeed a concern?

mcgyver5
  • 6,807
  • 2
  • 24
  • 45

1 Answers1

0

There have since been updates from the Apache Struts Team:

http://struts.apache.org/announce.html#a20140424

mcgyver5
  • 6,807
  • 2
  • 24
  • 45