Eric Yang created CHUKWA-822:
--------------------------------

             Summary: Update struts version to avoid security hole
                 Key: CHUKWA-822
                 URL: https://issues.apache.org/jira/browse/CHUKWA-822
             Project: Chukwa
          Issue Type: Bug
            Reporter: Eric Yang


Apache Struts was imported into Chukwa as dependency by velocity-tools.  Struts 
has a high severity security defect, which is described in CVE-2017-9805.  
Struts 2.13 patched this security defect, and Chukwa should consider upgradeing 
to the latest Apache Struts.



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

Reply via email to