Yes. Am 24.04.14 19:37, schrieb emilu@cse.concordia.ca: > Hello List, > > I am using tiles-default: > > extends="tiles-default"> > > class="org.apache.struts2.views.tiles.TilesResult" /> > > > class="ExampleAction"> > success_gui > > /WEB-INF/pages/errorinfo/ajax_error_check.jsp > > > Do I need this update below as well? Thank you! > > On 04/24/2014 11:32 AM, Rene Gielen wrote: >> In Struts 2.3.16.1, an issue with ClassLoader manipulation via request >> parameters was supposed to be resolved. Unfortunately, the correction >> wasn't sufficient. >> >> A security fix release fully addressing this issue is in preparation and >> will be released as soon as possible. >> >> Once the release is available, all Struts 2 users are strongly >> recommended to update their installations. >> >> * Until the release is available, all Struts 2 users are strongly >> recommended to apply the mitigation described [1] * >> >> Please follow the Apache Struts announcement channels [2][3][4][5] to >> stay updated regarding the upcoming security release. Most likely the >> release will be available within the next 72 hours. Please prepare for >> upgrading all Struts 2 based production systems to the new release >> version once available. >> >> - The Apache Struts Team. >> >> [1] http://struts.apache.org/announce.html#a20140424 >> [2] http://struts.apache.org/mail.html >> [3] http://struts.apache.org/announce.html >> [4] https://plus.google.com/+ApacheStruts/posts >> [5] https://twitter.com/TheApacheStruts > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: user-unsubscribe@struts.apache.org > For additional commands, e-mail: user-help@struts.apache.org > -- René Gielen IT-Neering.net Saarstrasse 100, 52062 Aachen, Germany Tel: +49-(0)241-4010770 Fax: +49-(0)241-4010771 Cel: +49-(0)163-2844164 http://twitter.com/rgielen --------------------------------------------------------------------- To unsubscribe, e-mail: user-unsubscribe@struts.apache.org For additional commands, e-mail: user-help@struts.apache.org