production use of a Struts 2.0.x website

2010-10-13 Thread Caoilte O'Connor
Hi, I'm investigating the changes that we will need for production use of website code base utilizing Struts2.. 1) = First of all, we are still using 2.0.x series Struts2. From what I can tell this means we are theoretically vulnerable to

Re: production use of a Struts 2.0.x website

2010-10-13 Thread Dave Newton
On Wed, Oct 13, 2010 at 10:37 AM, Caoilte O'Connor wrote: 1) = First of all, we are still using 2.0.x series Struts2. From what I can tell this means we are theoretically vulnerable to http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html There's no