Re: Confusion on Security Bulletin fix versions

2016-04-26 Thread Lukasz Lenart
2016-04-27 1:04 GMT+02:00 Doug Erickson : > On the Struts home page, it says, "We have released two older versions of > Apache Struts which *contain the latest security fixes.* Please read > announcement for* 2.3.20.3* ..." > > Those notes say, "This release addresses *two* potential security > vul

Confusion on Security Bulletin fix versions

2016-04-26 Thread Doug Erickson
On the Struts home page, it says, "We have released two older versions of Apache Struts which *contain the latest security fixes.* Please read announcement for* 2.3.20.3* ..." Those notes say, "This release addresses *two* potential security vulnerabilities," and then lists three issues, S2-029, S