[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-29 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15215689#comment-15215689 ] Naozumi Taromaru commented on WW-4507: -- I reproduced this issue. I use Struts 2.3.24.1 a

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-29 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15217298#comment-15217298 ] Naozumi Taromaru commented on WW-4507: -- The analysis of Rene (14/Jan/16 16:04) is wrong.

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-30 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15217857#comment-15217857 ] Naozumi Taromaru commented on WW-4507: -- > Historically we had many issues with solely re

[jira] [Created] (WW-4625) Struts 2 XSS vulnerability with when is used.

2016-04-03 Thread Naozumi Taromaru (JIRA)
Naozumi Taromaru created WW-4625: Summary: Struts 2 XSS vulnerability with when is used. Key: WW-4625 URL: https://issues.apache.org/jira/browse/WW-4625 Project: Struts 2 Issue Type: Bug

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-04-03 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15223734#comment-15223734 ] Naozumi Taromaru commented on WW-4507: -- I created new issue. https://issues.apache.org/j

[jira] [Commented] (WW-4625) Struts 2 XSS vulnerability with when is used.

2016-05-10 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4625?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15277847#comment-15277847 ] Naozumi Taromaru commented on WW-4625: -- If about workaround of 2.3.28 or before, I think