Hi Moritz,
On 09/02/2012 21:16, Moritz Mühlenhoff wrote:
There's a new issues, which affects 1.x:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1007
From [1], it seems there is no actual fix for this issue :(
I'll contact Struts Security Team on this matter.
[1]
http://secpod.org/advisories/SecPod_Apache_Struts_Multiple_Parsistant_XSS_Vulns.txt
--
Damien - Debian Developper
http://wiki.debian.org/DamienRaudeMorvan
__
This is the maintainer address of Debian's Java team
<http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
Please use
[email protected] for discussions and questions.