struts-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Lukasz Lenart <lukaszlen...@apache.org>
Subject [VOTE] Struts 2.3.31
Date Wed, 12 Oct 2016 05:29:23 GMT
The Apache Struts 2.3.31 test build is now available. With this release:

Two security bulletins were addresses with this release
- Possible path traversal in the Convention plugin S2-042
- Using the Config Browser plugin in production S2-043

Bugs
[WW-4601] - webconsole can always be accessed
[WW-4628] - Space character and includeParams
[WW-4659] - Exception starting filter struts2
java.lang.IncompatibleClassChangeError: Implementing class
[WW-4663] - NullPointerException when displaying a form without action attribute
[WW-4667] - ParametersInterceptor excludeParams only applies to first
instance of params interceptor in paramsPrepareParamsStack
[WW-4669] - Struts 2.5.1 gives errors on unexpected action names
[WW-4675] - Select box does not pre-select chosen values

Improvements
[WW-4674] - StrutsPrepareAndExecuteFilter should check for response
commited status
[WW-4685] - Allow directly accessing I18N keys from Tiles defintions

Security note:
This release fixes three potential security vulnerabilities as
mentioned in the Version Notes

Release notes:
* https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.3.31

Distribution:
* https://dist.apache.org/repos/dist/dev/struts/2.3.31/

Maven 2 staging repository:
* https://repository.apache.org/content/repositories/staging/

Once you have had a chance to review the test build, please respond
with a vote on its quality:

[ ] Leave at test build
[ ] Alpha
[ ] Beta
[ ] General Availability (GA)

Everyone who has tested the build is invited to vote. Votes by PMC
members are considered binding. A vote passes if there are at least
three binding +1s and more +1s than -1s.

The vote will remain open for at least 24 hours, longer upon request.
A vote can be amended at any time to upgrade or downgrade the quality
of the release based on future experience. If an initial vote
designates the build as "Beta", the release will be submitted for
mirroring and announced to the user list. Once released as a public
beta, subsequent quality votes on a build may be held on the user
list.

As always, the act of voting carries certain obligations. A binding
vote not only states an opinion, but means that the voter is agreeing
to help do the work.


Kind regards
--
Ɓukasz
+ 48 606 323 122 http://www.lenart.org.pl/

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@struts.apache.org
For additional commands, e-mail: dev-help@struts.apache.org


Mime
View raw message