Get a Pentest and security assessment of your IT network.

News

Apache Struts security update fixes critical vulnerabilities

Apache Software Foundation has released Struts 2.3.15.1, a security update for its Java Web application development framework. The new release addresses two vulnerabilities that stem from issues in the implementation of the DefaultActionMapper class and its “action:”, “redirect:” and “RedirectAction:” prefixes in particular. Struts developers have added code that sanitizes the “action:”-prefixed information and have removed support for the “red” and “action” prefixes. The developers recommend replacing them in the code with fixed navigation rules.”]

Source: https://www.csoonline.com/article/2133799/apache-struts-security-update-fixes-critical-vulnerabilities.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months