Re: [EXTERNAL] Re: Question Regarding Recent Security Announcement

2018-11-05 Thread Lukasz Lenart
pon., 5 lis 2018 o 13:33 David Dillard napisaƂ(a): > > Ok, that addresses one question, but still leaves one: why is it being > recommended to update File Upload NOW due to a possible DoS, when Struts has > been using a version of File Upload with no documented DoS issue for the last > six rele

RE: [EXTERNAL] Re: Question Regarding Recent Security Announcement

2018-11-05 Thread David Dillard
Ok, that addresses one question, but still leaves one: why is it being recommended to update File Upload NOW due to a possible DoS, when Struts has been using a version of File Upload with no documented DoS issue for the last six releases??? Or put another way, Struts 2.3.35 uses File Upload 1.