home.social

#struts — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #struts, aggregated by home.social.

  1. It's been a #struts and #lemontwigs day at work, getting things accomplished.
    Then I checked the news, I think #seanrowe is next 😟
    #music #nowlistening

  2. #Struts: A recently patched Critical Apache Struts 2 #vulnerability tracked as CVE-2024-53677 (CVSS: 9.5) is actively exploited by attackers allowing uploading malicious files like web shells:
    👇
    bleepingcomputer.com/news/secu

  3. Almost exactly a year ago, Rapid7 put out a technical analysis of Apache #Struts 2 CVE-2023-50164 that said:

    * Exploit payloads were going to need to be customized to the target

    * It wasn't clear that there was any critical mass of remotely exploitable applications out of the box

    * The reports of exploitation in the wild all appeared to be unsuccessful attempts rather than IRL compromises of production systems.

    attackerkb.com/topics/pe3CCtOE

    Fast-forward to CVE-2024-53677 and we can repeat the above verbatim, with one pretty notable exception — the "fixed" version that ostensibly remediates the vulnerability actually doesn't, and code-level changes are required (to migrate away from the vulnerable file upload interceptor) to actually remediate it. Also the "fixed" release (6.4.0) appears to have gone out a year ago? No idea. Big ups to @fuzz for the analysis!

    attackerkb.com/assessments/28f

  4. #Struts: New Critical #RCE #Vulnerability CVE-2023-50164 Discovered in Apache #Struts 2 - Patch Now!

    The vulnerability affects Apache Struts versions 2.0.0 - 2.5.32 and 6.0.0 - 6.3.0.1

    thehackernews.com/2023/12/new-

  5. The support plugin minor version 1.4.3 is now released. This version is based on the latest version 6.1.2 and 1.9.3 version to simplify development.

    bit.ly/s2-cloud

  6. New plugin version 5.0.3 released. This version is based on the latest version 6.1.2, 3.7.0 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

  7. New #Struts2 #jQuery plugin version 5.0.3 released. This version is based on the latest #Struts version 6.1.2, #jquery 3.7.0 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

    #java #javascript #webdevelopment #webdev #RELEASE #struts #jqueryui

  8. New #Struts2 #jQuery plugin version 5.0.3 released. This version is based on the latest #Struts version 6.1.2, #jquery 3.7.0 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

    #java #javascript #webdevelopment #webdev #RELEASE #struts #jqueryui

  9. Bypassing OGNL sandboxes for fun and charities

    // by @pwntester @githubsecurity

    “Object Graph Notation Language ( #OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache #Struts and Atlassian #Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

    github.blog/2023-01-27-bypassi

  10. Bypassing OGNL sandboxes for fun and charities

    // by @pwntester @githubsecurity

    “Object Graph Notation Language ( #OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache #Struts and Atlassian #Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

    github.blog/2023-01-27-bypassi

  11. Bypassing OGNL sandboxes for fun and charities

    // by @pwntester @githubsecurity

    “Object Graph Notation Language ( #OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache #Struts and Atlassian #Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

    github.blog/2023-01-27-bypassi

  12. Bypassing OGNL sandboxes for fun and charities

    // by @pwntester @githubsecurity

    “Object Graph Notation Language ( #OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache #Struts and Atlassian #Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

    github.blog/2023-01-27-bypassi

  13. Bypassing OGNL sandboxes for fun and charities

    // by @pwntester @githubsecurity

    “Object Graph Notation Language ( #OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache #Struts and Atlassian #Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

    github.blog/2023-01-27-bypassi

  14. New plugin version 5.0.2 released. This version is based on latest Apache Struts version 6.1.1 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

  15. New #Struts2 #jQuery plugin version 5.0.2 released. This version is based on latest Apache Struts version 6.1.1 and it includes some improvement's and bug fixes.

    bit.ly/s2jquery

    #java #javascript #webdevelopment #webdev #RELEASE #struts #jqueryui #webdev

  16. 1.x was the very first web framework I learned in my career ~2008. Glad to hear it's still progressing!

    Version 6 was just released: "Until version 6.0.0, each application using Struts had to use API 2.5 at least. This version of Servlet API is over 17 years old now, while Struts is 20 years old". softwaremill.com/whats-new-in- by @softwaremill

  17. Are there any The #struts #fans on here? They are such a #fun live show band! If you get a chance to see them #livemusic grab it!

  18. Right now I'm reading a #Struts book, which was the way to create web sites with Java in the early years of the Third Age.

    I hated it back then, so it would be interesting how it compares to the current horrorfest that is completion-driven webdev.

  19. Apache issues advisory warning of serious vulnerability in Struts framework buff.ly/3leaFpO #security #Apache #Struts