[SECURITY] CVE-2013-2251: Apache Continuum affected by Remote Co

看板Bugtraq作者時間11年前 (2014/06/14 02:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
CVE-2013-2251: Apache Continuum affected by Remote Command Execution Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Continuum 1.3.1 to Continuum 1.4.1 Description: Apache Continuum is affected by a vulnerability in the version of the = Struts library being used, which allows a malicious user to run code on the server remotely. More = details about the vulnerability can be found at http://struts.apache.org/2.3.x/docs/s2-016.html. Mitigation: All users are recommended to upgrade to Continuum 1.4.2, which is not = affected by this issue. References: http://continuum.apache.org/security.html
文章代碼(AID): #1JcqEY1T (Bugtraq)