Skip to content
Discussion options

You must be logged in to vote

Hi @bbhansali1,

The Struts-version 1.5+ is for JakartaEE 9+ where the namespace is changed from javax to jakarta.
The Struts-version 1.4.x (currently 1.4.5) is for JakartaEE 8, where the namespace is unchanged (javax). So this version should be for you.

Hint: The only difference between 1.4.x and 1.5.x will be the namespace.

And yes, the version 1.4.5 also address all the vulnerabilities, which you will find in the README. The newest vulnerability CVE-2023-49735 / #23 - Apache Tiles: Unvalidated input may lead to path traversal and XXE will also be resolved in the near future.

I hope I could help you
Greetings
Stefan

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
3 replies
@bbhansali1
Comment options

@ste-gr
Comment options

@ste-gr
Comment options

Answer selected by bbhansali1
Comment options

You must be logged in to vote
1 reply
@ste-gr
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants