Thanks to visit codestin.com
Credit goes to github.com

Skip to content
forked from apache/struts1

Apache Struts 1 CVE issues fix

lawrencexu/struts1

 
 

Repository files navigation

struts1

Build Status

Apache Struts 1 CVE issues fix

Fix the issues described in https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-6117/version_id-164424/Apache-Struts-1.3.5.html

CVE-2015-0899
Solution is in this commit https://github.com/lawrencexu/struts1/commit/646632ea5f7081a73a4b17cfa489b4fc2c8cddd8.

CVE-2014-0114
Solution:
Upgrade commons-beanutils lib to latest 1.9.4.
More details in http://commons.apache.org/proper/commons-beanutils/javadocs/v1.9.4/RELEASE-NOTES.txt.

CVE-2016-1181
CVE-2016-1182
Solution:
Do nothing. As these two depends on CVE-2014-0114 which is fixed already.
And according to comments in link1 and link2, we should not include the mentioned commit as a general solution.

About

Apache Struts 1 CVE issues fix

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages

  • Java 91.9%
  • HTML 7.8%
  • Other 0.3%