home.social

#struts — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #struts, aggregated by home.social.

fetched live
  1. The hardest part of legacy modernisation is often not the business logic — it’s the platform drift underneath it. Containers & #Java evolve while old frameworks stay frozen. @spoole167 explores why #Struts & #JakartaEE now fundamentally diverge: javapro.io/2026/06/18/2-the-ja

    @HeroDevs

  2. Most legacy systems don’t fail dramatically. They quietly become impossible to patch or staff. That’s why old #Struts apps still create operational risk in 2026. @spoole167 explores why modernising Struts is usually a corridor — not a cliff edge: javapro.io/2026/06/16/1-why-st
    @HeroDevs

  3. Many legacy systems don’t break because the code fails. They break because the platform keeps moving forward. That’s where old #Struts apps hit the #Jakarta wall.

    @spoole167 explains why #Tomcat10 & modern #Java containers leave Struts behind: javapro.io/2026/06/18/2-the-ja

    @HeroDevs

  4. The hardest part of legacy modernisation is often not the business logic — it’s the platform drift underneath it. Containers & #Java evolve while old frameworks stay frozen. @spoole167 explores why #Struts & #JakartaEE now fundamentally diverge: javapro.io/2026/06/18/2-the-ja

  5. It's been a #struts and #lemontwigs day at work, getting things accomplished.
    Then I checked the news, I think #seanrowe is next 😟
    #music #nowlistening

  6. #Struts: A recently patched Critical Apache Struts 2 #vulnerability tracked as CVE-2024-53677 (CVSS: 9.5) is actively exploited by attackers allowing uploading malicious files like web shells:
    👇
    bleepingcomputer.com/news/secu

  7. Almost exactly a year ago, Rapid7 put out a technical analysis of Apache #Struts 2 CVE-2023-50164 that said:

    * Exploit payloads were going to need to be customized to the target

    * It wasn't clear that there was any critical mass of remotely exploitable applications out of the box

    * The reports of exploitation in the wild all appeared to be unsuccessful attempts rather than IRL compromises of production systems.

    attackerkb.com/topics/pe3CCtOE

    Fast-forward to CVE-2024-53677 and we can repeat the above verbatim, with one pretty notable exception — the "fixed" version that ostensibly remediates the vulnerability actually doesn't, and code-level changes are required (to migrate away from the vulnerable file upload interceptor) to actually remediate it. Also the "fixed" release (6.4.0) appears to have gone out a year ago? No idea. Big ups to @fuzz for the analysis!

    attackerkb.com/assessments/28f

  8. #Struts: New Critical #RCE #Vulnerability CVE-2023-50164 Discovered in Apache #Struts 2 - Patch Now!

    The vulnerability affects Apache Struts versions 2.0.0 - 2.5.32 and 6.0.0 - 6.3.0.1

    thehackernews.com/2023/12/new-

  9. The support plugin minor version 1.4.3 is now released. This version is based on the latest version 6.1.2 and 1.9.3 version to simplify development.

    bit.ly/s2-cloud

  10. New plugin version 5.0.3 released. This version is based on the latest version 6.1.2, 3.7.0 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

  11. Bypassing OGNL sandboxes for fun and charities

    // by @pwntester @githubsecurity

    “Object Graph Notation Language ( #OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache #Struts and Atlassian #Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

    github.blog/2023-01-27-bypassi

  12. New plugin version 5.0.2 released. This version is based on latest Apache Struts version 6.1.1 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

  13. 1.x was the very first web framework I learned in my career ~2008. Glad to hear it's still progressing!

    Version 6 was just released: "Until version 6.0.0, each application using Struts had to use API 2.5 at least. This version of Servlet API is over 17 years old now, while Struts is 20 years old". softwaremill.com/whats-new-in- by @softwaremill

  14. Are there any The #struts #fans on here? They are such a #fun live show band! If you get a chance to see them #livemusic grab it!

  15. Right now I'm reading a #Struts book, which was the way to create web sites with Java in the early years of the Third Age.

    I hated it back then, so it would be interesting how it compares to the current horrorfest that is completion-driven webdev.

  16. Apache issues advisory warning of serious vulnerability in Struts framework buff.ly/3leaFpO #security #Apache #Struts