What is correct version to use for javax implementation? #22
-
|
We are trying to remediate all the vulnerabilities on Struts 1.2.9. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
|
Hi @bbhansali1, The Hint: The only difference between 1.4.x and 1.5.x will be the namespace. And yes, the version 1.4.5 also address all the vulnerabilities, which you will find in the README. The newest vulnerability CVE-2023-49735 / #23 - Apache Tiles: Unvalidated input may lead to path traversal and XXE will also be resolved in the near future. I hope I could help you |
Beta Was this translation helpful? Give feedback.
-
|
hi @ste-gr - any update if we are fixing this in 1.4.x releases? |
Beta Was this translation helpful? Give feedback.
Hi @bbhansali1,
The
Struts-version 1.5+ is for JakartaEE 9+ where the namespace is changed fromjavaxtojakarta.The
Struts-version 1.4.x (currently 1.4.5) is for JakartaEE 8, where the namespace is unchanged (javax). So this version should be for you.Hint: The only difference between 1.4.x and 1.5.x will be the namespace.
And yes, the version 1.4.5 also address all the vulnerabilities, which you will find in the README. The newest vulnerability CVE-2023-49735 / #23 - Apache Tiles: Unvalidated input may lead to path traversal and XXE will also be resolved in the near future.
I hope I could help you
Greetings
Stefan