Security experts warn that code showing malicious hackers how to exploit a newly-discovered Apache Struts bug is available online. In September 2017, Equifax disclosed that a failure to patch one of its Internet servers against a pervasive software flaw led to a breach that exposed personal data on 147 million Americans. The vulnerability affects all supported versions of Struts 2.3 and 2.5.17; the vulnerability affects versions 2.2.3.35, 2.4.35; 2.17.17. An alert about the Apache security update was posted Wednesday by the San Francisco software company whose researchers discovered the bug.”]
Source: https://krebsonsecurity.com/2018/08/experts-urge-rapid-patching-of-struts-bug/

