[ANN] Apache Struts 6.4.0

2024-04-20 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.4.0 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The

CVE-2023-41835: Apache Struts: excessive disk usage

2023-12-09 Thread Lukasz Lenart
Severity: moderate Affected versions: - Apache Struts 2.0.0 through 2.5.31 - Apache Struts 6.1.2.1 through 6.3.0 Description: When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the

[ANN] Apache Struts 6.3.0.2 & 2.5.33

2023-12-07 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts versions 6.3.0.2 & 2.5.33 are available as “General Availability” releases. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications.

CVE-2023-50164: Apache Struts: File upload component had a directory traversal vulnerability

2023-12-07 Thread Lukasz Lenart
Severity: critical Affected versions: - Apache Struts 2.0.0 through 2.5.32 - Apache Struts 6.0.0 through 6.3.0.1 Description: An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to

[ANN] Apache Struts 2.5.x EOL

2023-10-31 Thread Lukasz Lenart
The Apache Struts Project Team would like to inform you that the Struts 2.5.x web framework will reach its end of life in 6 months and won’t be officially supported. Please check the following reading to find more details. https://struts.apache.org/struts25-eol-announcement Apache Struts 2.5.x

[ANN] Apache Struts 6.3.0.1, 6.1.2.2, 2.5.32

2023-09-13 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts versions 6.3.0.1, 6.1.2.2 & 2.5.32 are available as “General Availability” releases. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web

[ANN] Apache Struts 6.3.0

2023-09-05 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.3.0 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The

[ANN] Apache Struts 6.2.0

2023-07-10 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 6.2.0 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2023#a20230710 Below is a full list of all changes. Bug WW-4434 - datetextfield.ftl is

[ANN] Apache Struts 6.1.2.1

2023-06-13 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.1.2.1 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The

[ANN] Apache Struts 2.5.31

2023-06-13 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 2.5.31 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The

[ANN] Apache Struts 6.1.2

2023-03-10 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 6.1.2 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2023#a20230310 Below is a full list of all changes. Improvement WW-5285 - Upgrade

[ANN] Apache Struts 6.1.1 (proper list of issues)

2022-11-28 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 6.1.1 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2022#a20221128 Below is a full list of all changes. Bug WW-3529 -

Re: [ANN] Apache Struts 6.1.1

2022-11-28 Thread Lukasz Lenart
Please ignore this announcement, it contains a wrong set of addressed issues. I will prepare a new one with a proper set of addressed tickets. Sorry for inconvenience -- Łukasz pon., 28 lis 2022 o 15:33 Lukasz Lenart napisał(a): > > The Apache Struts group is pleased to announce that

[ANN] Apache Struts 6.1.1

2022-11-28 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 6.1.1 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2022#a20220915 Below is a full list of all changes. Bug WW-5185 - TilesDefinition is not

[ANN] Apache Struts ver. 6.0.3 GA

2022-09-16 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 6.0.3 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2022#a20220915 Below is a full list of all changes. Bug: WW-5185 - TilesDefinition is not

[ANN] Apache Struts 2 ver. 6.0.0

2022-06-09 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts 2 ver. 6.0.0 is available as a "General Availability" release. The GA designation is our highest quality grade. **Version change** You may be surprised by the version change, previously we have been using Struts 2.5.x versioning

[ANN] Apache Struts 2.5.30

2022-04-11 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.30 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2022#a20220404 Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready

[ANN] Apache Struts 2.5.29

2022-01-22 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.29 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2022#a20220122 Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready

[ANN] Apache Struts 2.5.28.3

2022-01-02 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.28.3 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2022#a20220102 This release addresses the Log4j vulnerability CVE-2021-44832 by using the

[ANN] Apache Struts 2.5.28.2

2021-12-23 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.28.2 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2021.html#a20211223 This release addresses the Log4j vulnerability CVE-2021-45105 by using the

[ANN] Apache Struts 2.5.28.1

2021-12-17 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.28.1 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2021.html#a20211217 This release addresses the Log4j vulnerability CVE-2021-45046 by using the

[ANN] Apache Struts 2.5.28

2021-12-14 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.28 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2021.html#a20211212 Apache Struts 2 is an elegant, extensible framework for creating

[ANN] Apache Struts 2.5.27

2021-11-16 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.27 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce-2021.html#a2026 Apache Struts 2 is an elegant, extensible framework for creating

[ANN] [SECURITY] Apache Struts 2.0.0 - 2.5.25: Potential RCE when using forced evaluation - CVE-2020-17530

2020-12-08 Thread Lukasz Lenart
The Apache Struts Security team would like to announce that forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected products Apache Struts 2.0.0 - 2.5.25 Problem Some of the tag's attributes could perform a double evaluation if a

[ANN] Struts 2.5.26

2020-12-06 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.26 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce.html#a20201206 Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready

[ANN] Struts 2.5.25

2020-09-29 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.25 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce.html#a20200928 Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready

[ANN] Apache Struts 2.5.22

2019-11-30 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.22 is available as a “General Availability” release. The GA designation is our highest quality grade. https://struts.apache.org/announce.html#a20191129 Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready

[ANN] Apache Struts 2.3.x EOL

2019-09-16 Thread Lukasz Lenart
As announced over 6 months ago, Apache Struts 2.3.x web framework series reached its end of life and won’t be longer officially supported. Please check the following reading to find more details: https://struts.apache.org/struts23-eol-announcement https://struts.apache.org/announce#a20190912

[ANN] Apache Struts 2.3.37 GA

2019-01-16 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.37 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.5.20 GA

2019-01-16 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.20 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.3.x End-Of-Life (EOL) Announcement

2018-11-14 Thread Lukasz Lenart
The Apache Struts Project Team would like to inform you that the Struts 2.3.x web framework will reach its end of life in 6 months and won’t be longer officially supported. https://struts.apache.org/announce#a20181114 This announcement takes place on 2018-11-14 and starting from that date we

[ANN] [SECURITY] Immediately upgrade commons-fileupload to version 1.3.3 when running Struts 2.3.36 or prior

2018-11-05 Thread Lukasz Lenart
The Apache Struts Team recommends to immediately upgrade your Struts 2.3.36 based projects to use the latest released version of Commons FileUpload library, which is currently 1.3.3. This is necessary to prevent your publicly accessible web site from being exposed to possible Remote Code Execution

Re: [ANN] [SECURITY] Immediately upgrade commons-fileupload to version 1.3.1 when running Struts 2.3.36

2018-11-04 Thread Lukasz Lenart
I meant commons-fileupload version 1.3.3, sorry for that. Kind regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ niedz., 4 lis 2018 o 10:30 Lukasz Lenart napisał(a): > > The Apache Struts Team recommends to immediately upgrade your Struts 2.3.36 > based projects to use t

[ANN] [SECURITY] Immediately upgrade commons-fileupload to version 1.3.1 when running Struts 2.3.36

2018-11-04 Thread Lukasz Lenart
The Apache Struts Team recommends to immediately upgrade your Struts 2.3.36 based projects to use the latest released version of Commons FileUpload library, which is currently 1.3.1. This is necessary to prevent your publicly accessible web site from being exposed to possible DoS attacks [1] [2].

[ANN] Apache Struts 2.5.18 GA

2018-10-15 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.18 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Extended list of Struts version affected by CVE-2018-11776 - RCE when using alwaysSelectFullNamespace

2018-09-24 Thread Lukasz Lenart
Hello, We received an additional information about possible affected versions of Struts. Please read the bulletin [1] to find more details about the vulnerability and upgrade to the latest version of Struts if you are running one of those versions: - Struts 2.0.4 - Struts 2.3.34 - Struts 2.5.0 -

[ANN] A crafted XML request can be used to perform a DoS attack when using the Struts REST plugin

2018-03-27 Thread Lukasz Lenart
The Apache Security Struts Team recommends to immediately upgrade your Struts 2 based projects to use the latest released version of the Apache Struts. This is necessary to prevent your publicly accessible web site, which is using the Struts REST plugin and performing XML serialisation, from being

[ANN] Immediately upgrade commons-fileupload to version 1.3.3

2018-03-27 Thread Lukasz Lenart
The Apache Struts Team recommends to immediately upgrade your Struts 2 based projects to use the latest released version of Commons FileUpload library, which is currently 1.3.3. This is necessary to prevent your publicly accessible web site from being exposed to possible Remote Code Execution

[ANN] Apache Struts 2.5.16 GA

2018-03-16 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.16 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] New version of the Apache Struts Maven Archetypes

2018-02-06 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that the Apache Struts Maven Archetypes are available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications.

[ANN] [APACHE STRUTS] Security Bulletin S2-055: impact increased to High (related to CVE-2017-7525 - JSON Jackson library)

2017-12-11 Thread Lukasz Lenart
Hi, After further clarification we increased impact of a vulnerability reported to us and described as S2-055 to High. The vulnerability exists in a JSON Jackson library and it's registered under CVE-2017-7525. Please read the bulletin [1] and apply possible solutions. This vulnerability impacts

[ANN] Apache Struts 2.5.14.1 GA with Security Fixes Release

2017-12-01 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.14.1 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.5.14 GA

2017-11-27 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.14 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.3.34 General Availability with Security Fixes Release

2017-09-07 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.34 is available as a “General Availability” release. The GA designation is our highest quality grade. This release addresses these potential security vulnerabilities: - S2-050 A regular expression Denial of Service when using

Re: [ANN] Apache Struts 2.5.13 GA with Security Fixes Release

2017-09-05 Thread Lukasz Lenart
2017-09-05 15:17 GMT+02:00 Lukasz Lenart <lukaszlen...@apache.org>: > - S2-052 Possible Remote Code Execution attack when using the Struts REST > plugin with XStream handler to handle XML payloads > http://struts.apache.org/docs/s2-050.html It's supposed to be http://struts.

[ANN] Apache Struts 2.5.13 GA with Security Fixes Release

2017-09-05 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.13 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts: S2-049 Security Bulletin update

2017-08-10 Thread Lukasz Lenart
This is an update of the recently announced Security Bulletin S2-049 - http://struts.apache.org/docs/s2-049.html The bulletin was extended with an additional information when the potential vulnerability can be present in your application. Please re-read the mentioned bulletin and apply required

[ANN] Apache Struts 2.5.12 GA with Security Fixes Release

2017-07-13 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.12 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2: possible RCE in the Struts Showcase app in the Struts 1 plugin example in the Struts 2.3.x series

2017-07-07 Thread Lukasz Lenart
A potential security vulnerability was reported in the Struts 1 plugin used in the Struts 2.3.x series. It is possible to perform a Remote Code Execution attack if given construction exists in the vulnerable application. Please read the security bulletin for more details and inspect your

[ANN] [SECURITY] Struts Extras secure Multipart plugins GA - versions 1.1

2017-03-23 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that the Apache Struts 2 Secure Jakarta Multipart parser plugin 1.1 and Apache Struts 2 Secure Jakarta Stream Multipart parser plugin 1.1 are available as a “General Availability” release. The GA designation is our highest quality grade. These

[ANN] [SECURITY] Struts Extras secure Multipart plugins GA

2017-03-20 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that the Apache Struts 2 Secure Jakarta Multipart parser plugin and Apache Struts 2 Secure Jakarta Stream Multipart parser plugin are available as a “General Availability” release. The GA designation is our highest quality grade. These releases

[ANN] Apache Struts 2.3.32 GA with Security Fixe Release

2017-03-10 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.32 is available as a “General Availability” release. The GA designation is our highest quality grade. This release addresses one potential security vulnerability: - Possible Remote Code Execution when performing file upload based on

[ANN] Apache Struts 2.5.10.1 GA with Security Fixe Release

2017-03-08 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.10.1 is available as a “General Availability” release. The GA designation is our highest quality grade. This release addresses one potential security vulnerability: - Possible Remote Code Execution when performing file upload based on

[ANN] Apache Struts 2.5.10 GA

2017-02-03 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.10 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed to

[ANN] Apache Struts 2.5.5 GA

2016-10-21 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.5 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed to

[ANN] Apache Struts 2.3.31 General Availability with Security Fixes Release

2016-10-18 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.31 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.5.2 GA

2016-07-15 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.2 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed to

[ANN] Apache Struts 2.3.30 GA

2016-07-15 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.30 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Struts 2.5.1 General Availability

2016-06-17 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5.1 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed to

[ANN] Apache Struts 2.3.29 General Availability with Security Fixes Release

2016-06-17 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.29 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.3.20.3 GA & Apache Struts 2.3.24.3 GA

2016-04-21 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.20.3 and Struts 2.3.24.3 are available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The

[ANN] Apache Struts 2.3.28.1 GA

2016-04-21 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.28.1 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Apache Struts 2.3.28 GA

2016-03-22 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.28 is available as a “General Availability” release. The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed

[ANN] Struts 2.5-BETA3 Beta release available

2016-01-27 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.5-BETA3 is available as a "Beta" release. The Beta designation indicates that we believe the distribution needs wider testing before being upgraded to a "General Availability" release. Your input is essential. Apache Struts 2 is an