Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-15555

Xwiki 9.11.5 - Apache Struts vulnerability Check

    XMLWordPrintable

Details

    • High
    • Hard

    Description

      Hello,

        As per https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11776 a critical vulnerability has been discovered in the Apache Struts web application framework tool which is being actively exploited in the wild.  

          We have noticed that Xwiki 9.11.5 is using the below version of struts. Please confirm if this version is vulnerable.

      struts 1.3.10

      Kindly recommend if there is any fix available for this.

      Thanks in advance

      Steny

       

      Attachments

        Issue Links

          Activity

            People

              tmortagne Thomas Mortagne
              steny.james steny james
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: