struts-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Markus Fischer <Markus.Fisc...@knipp.de>
Subject Is the Dojo plugin version shipped with Struts 2.3.x vulnerable?
Date Mon, 06 Oct 2014 13:42:37 GMT
Hi all,

I have a question regarding the patch level of the Dojo plugin shipped
with Struts 2.3.x. According to the Apache Struts 2 Documentation (see
[1]), Struts 2.3.x ships with Dojo 0.4.3, which is vulnerable to two
major security issues (CVE-2010-2276 and CVE-2010-2272, see [2]).

Is a Struts 2.3.x system using the Dojo plugin vulnerable to these
security issues, or have they been fixed somehow?

Any information or links to further reading greatly appreciated.

Cheers,
Markus

[1] http://struts.apache.org/release/2.3.x/docs/dojo-head.html

[2]
http://www.cvedetails.com/vulnerability-list/vendor_id-7641/product_id-12940/version_id-70187/Dojotoolkit-Dojo-0.4.3.html



---------------------------------------------------------------------
To unsubscribe, e-mail: user-unsubscribe@struts.apache.org
For additional commands, e-mail: user-help@struts.apache.org


Mime
View raw message