Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Slashdot videos: Now with more Slashdot!

  • View

  • Discuss

  • Share

We've improved Slashdot's video section; now you can view our video interviews, product close-ups and site visits with all the usual Slashdot options to comment, share, etc. No more walled garden! It's a work in progress -- we hope you'll check it out (Learn more about the recent updates).

×

+ - Apache Struts Zero Day Not Fixed by Patch

Submitted by Trailrunner7
Trailrunner7 (1100399) writes "The Apache Software Foundation today released an advisory warning that a patch issued in March for a zero-day vulnerability in Apache Struts did not fully patch the bug in question.

Officials said a new patch is in development and will be released likely within the next 72 hours, said Rene Gielen of the Apache Struts team.

On March 2, a patch was made available for a ClassLoader vulnerability in Struts up to version 2.3.16.1. An attacker would be able to manipulate the ClassLoader via request parameters. Apache said the fix was insufficient to repair the vulnerability."
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Apache Struts Zero Day Not Fixed by Patch

Comments Filter:

According to the latest official figures, 43% of all statistics are totally worthless.

Working...