Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Vulnerability struts2-core-2.3.20.1.jar

Asif Khan
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 20, 2017

struts2-core-2.3.20.1.jar  this file has serious vulnerability, is there a fix available from Atlassian, this file is in may locations see below

/opt/atlassian-crowd-2.8.4/crowd-webapp/WEB-INF/lib/struts2-core-2.3.20.1.jar

  • Installation Path:

/opt/atlassian-crowd-2.8.4/demo-webapp/WEB-INF/lib/struts2-core-2.3.20.1.jar

  • Installation Path:

/opt/atlassian-crowd-2.8.4/crowd-openidserver-webapp/WEB-INF/lib/struts2-core-2.3.20.1.jar

  • Installation Path:

/opt/atlassian-crowd-2.8.4/crowd-openidclient-webapp/WEB-INF/lib/struts2-core-2.3.20.1.jar

1 answer

0 votes
Bruno Vincent
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 21, 2017

Hi Asif,

Yes, there is a fix available. You will actually need to upgrade your Crowd installation. Please take a look at this page: https://confluence.atlassian.com/crowd/crowd-security-advisory-2017-03-10-876857916.html

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events