Details
-
Bug
-
Resolution: Solved By
-
Major
-
9.11.5
-
High
-
Hard
-
Description
Hello,
As per https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11776 a critical vulnerability has been discovered in the Apache Struts web application framework tool which is being actively exploited in the wild.
We have noticed that Xwiki 9.11.5 is using the below version of struts. Please confirm if this version is vulnerable.
struts 1.3.10
Kindly recommend if there is any fix available for this.
Thanks in advance
Steny
Attachments
Issue Links
- depends on
-
XWIKI-17902 Get rid of Struts
-
- Closed
-