Slashdot Mirror


Apache Struts Zero Day Not Fixed By Patch

Trailrunner7 (1100399) writes "The Apache Software Foundation released an advisory warning that a patch issued in March for a zero-day vulnerability in Apache Struts did not fully patch the bug in question. Officials said a new patch is in development and will be released likely within the next 72 hours, said Rene Gielen of the Apache Struts team. On March 2, a patch was made available for a ClassLoader vulnerability in Struts up to version 2.3.16.1. An attacker would be able to manipulate the ClassLoader via request parameters. Apache said the fix was insufficient to repair the vulnerability."

7 of 15 comments (clear)

  1. Of course, the warning is three days old by Anonymous Coward · · Score: 1

    So... the patch should be out any moment.

  2. All zero-day... by Ksevio · · Score: 1

    Isn't that the case for all zero-day exploits? If it were already patched then it wouldn't really fit the criteria.

  3. Gee... by ericloewe · · Score: 2

    Must they absolutely advertise their bugs before they're fixed? Nothing wrong with being open after it's been patched, but this is like "Hey, we tried to fix a bug and failed, so you can totally go check our non-fix to figure out how to exploit this!"

  4. Good thing... by Bill_the_Engineer · · Score: 4, Insightful

    Apache struts announced another general availability release that has the fix on April 24th.

    This is why you shouldn't read a blog post when the source material is just as easy to read.

    --
    These comments are my own and do not necessarily reflect the views or opinions of my employer or colleagues...
  5. What? There is still an Apache Struts? by hax4bux · · Score: 4, Funny

    How about that?

  6. Comment removed by account_deleted · · Score: 5, Insightful

    Comment removed based on user account deletion

  7. Why would they strut something like that? by jeffb+(2.718) · · Score: 1

    ...never mind.