Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apache Struts Vulnerability #2622

Open
rockliffelewis opened this issue Dec 16, 2024 · 1 comment
Open

Apache Struts Vulnerability #2622

rockliffelewis opened this issue Dec 16, 2024 · 1 comment
Assignees
Milestone

Comments

@rockliffelewis
Copy link

rockliffelewis commented Dec 16, 2024

As detailled in CVE-2024-53677 (https://cwiki.apache.org/confluence/display/WW/S2-067)

IPT is using a vulnerable version of apache struts, and does implement the file upload interceptor.

Please update apache struts and change the file upload functionality

@mike-podolskiy90
Copy link
Contributor

Thanks for reporting this issue. I'm working on migrating to Struts 6.x.x

@mike-podolskiy90 mike-podolskiy90 self-assigned this Dec 16, 2024
@mike-podolskiy90 mike-podolskiy90 added this to the 3.2 milestone Dec 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants