Re: Struts2 remote commands execution

2010-07-13 Thread Greg Lindholm
Thanks for pushing this, your right it is critical and needs to be fixed asap. On Sat, Jul 10, 2010 at 4:02 AM, Meder Kydyraliev mede...@gmail.com wrote: There's a critical remote commands execution vulnerability in XWork(used by Struts2), which fixed in 2.2.0, which isn't released yet but can

Re: Struts2 remote commands execution

2010-07-13 Thread Johannes Geppert
is version 2.2.0 also available with maven? Johannes Meder Kydyraliev-2 wrote: There's a critical remote commands execution vulnerability in XWork(used by Struts2), which fixed in 2.2.0, which isn't released yet but can be downloaded here: http://people.apache.org/builds/struts/2.2.0/

Re: Struts2 remote commands execution

2010-07-13 Thread Lukasz Lenart
2010/7/13 Johannes Geppert jo...@web.de: is version 2.2.0 also available with maven? Not yet, still in stagging repo only and still under the Vote :-( Regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ Kapituła Javarsovia 2010 http://javarsovia.pl

Re: Struts2 remote commands execution

2010-07-10 Thread Lukasz Lenart
2010/7/10 Meder Kydyraliev mede...@gmail.com: There's a critical remote commands execution vulnerability in XWork(used by Struts2), which fixed in 2.2.0, which isn't released yet but can be downloaded here: http://people.apache.org/builds/struts/2.2.0/ More details about this vulnerability