Reputation: 175
I am working on a legacy application and recently I came to know there are vulnerabilities in struts 1 and struts 2 versions and found the following link through Google.
https://www.cvedetails.com/cve/CVE-2016-1182/
Here I am confused how to remediate these vulnerabilities. Can any one guide me in this.
Upvotes: 0
Views: 1193
Reputation: 91
The best thing to do would be to upgrade to the latest version. Struts 1 is End of Life and won't receive any updates to fix any issues that still exist.
The latest versions of Struts 2 don't appear to have any published CVEs currently so I would recommend upgrading as soon as you can. It isn't a simple task to migrate to Struts2 with the huge differences but short of fixing the vulnerabilities in Struts1 yourself there is very little else you can do.
Upvotes: 1
Reputation: 56
Apache Struts 1 reached it's EOL in December, 2008. Any official support was ceased at that time.
I've listed 3 options I've found while researching the same thing:
Upvotes: 1