Hi Team,
I found one critical Vulnerabilities (97610 - Apache Struts 2.3.5 - 2.3.31 / 2.5.x < 2.5.10.1 Jakarta Multipart Parser RCE) in bamboo application. We tried to download struts2-core-2.5.20 .jar from apache strut site but its not working, even I tried from maven repository but no luck. So need help from this community to resolve my issue.
Application not started with struts2-core-2.5.20.jar file so I have to roll back with old file again to run application properly.
Bamboo : version 5.13.0.1 build 51314
File Location : /opt/atlassian/bamboo/atlassian-bamboo/WEB-INF/lib
File Name : struts2-core-2.5.1-atlassian-10.jar
Need greater version than 2.5.1
Hi,
your version is over EOL so I think you have only two options.
Can you make upgrade?
HI Petr,
Thanks for quick reply
I need to check if i can upgrade.
Regards,
Jitendra
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.