Apache Struts Vulnerability - CVE-2017-9791

2017-07-23 Thread Chunduru, Krishnachaithanya
Hi All, Can someone please confirm if Apache 2.4.10 is vulnerable to the CVE-2017-9791. We came to know that Apache which is having Apache Struts version 2.3.x with Struts 1 plugin and Struts 1 action is highly vulnerable . If exploited, this vulnerability would allow a remote code execution

RE: Apache Struts Vulnerability - CVE-2017-9791

2017-07-24 Thread Chunduru, Krishnachaithanya
Users Mailing List Subject: Re: Apache Struts Vulnerability - CVE-2017-9791 2017-07-23 14:20 GMT+02:00 Chunduru, Krishnachaithanya <krishnachaithanya.chund...@broadridge.com>: > Can someone please confirm if Apache 2.4.10 is vulnerable to the > CVE-2017-9791. I assume you

RE: Apache Struts Vulnerability - CVE-2017-9791

2017-07-24 Thread Chunduru, Krishnachaithanya
: Monday, July 24, 2017 1:16 PM To: Struts Users Mailing List Subject: Re: Apache Struts Vulnerability - CVE-2017-9791 2017-07-24 9:36 GMT+02:00 Chunduru, Krishnachaithanya <krishnachaithanya.chund...@broadridge.com>: > I was referring to Apache version we have i.e., 2.4.10. There is no suc