RE: CVE-2019-0233 is Struts v1 vulnerable?

2020-08-24 Thread Rayne Anderson
related to a dependent library—there’s no real relationship between S1 and S2. On Fri, Aug 21, 2020 at 15:39 Rayne Anderson wrote: > You are probably correct on due to the different frameworks. If I do need > > to test Struts v1 where do I obtain the test instructions from? I could >

RE: CVE-2019-0233 is Struts v1 vulnerable?

2020-08-21 Thread Rayne Anderson
(704) 501-0331 From: Lukasz Lenart To: Struts Users Mailing List Date: 08/21/2020 05:57 AM Subject:[EXTERNAL] Re: CVE-2019-0233 is Struts v1 vulnerable? pt., 21 sie 2020 o 11:30 Rayne Anderson napisał(a): > > I know that Apache Struts File upload CVE-2019-0233 appl

CVE-2019-0233 is Struts v1 vulnerable?

2020-08-21 Thread Rayne Anderson
I know that Apache Struts File upload CVE-2019-0233 applies to Struts v2. Does the CVE apply to Struts v1.3.8? If no one knows the answer I can find no explicit details of how to test for the vulnerability or what the code changes where made in Struts 2. How do I obtain this information? I hav