Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-prjv-jj26-wf8h] ClassLoader manipulation in Apache Struts #3170

Closed

Conversation

sunSUNQ
Copy link

@sunSUNQ sunSUNQ commented Dec 25, 2023

Updates

  • References
  • Source code location

Comments
Add patch link related to CVE-2014-0112.

@github-actions github-actions bot changed the base branch from main to sunSUNQ/advisory-improvement-3170 December 25, 2023 12:20
@shelbyc
Copy link
Contributor

shelbyc commented Dec 28, 2023

Hi @sunSUNQ, apache/struts@2e2da29 is appropriate for CVE-2014-0094 but doesn't correspond with CVE-2014-0112 having been fixed in 2.3.20, according to https://cwiki.apache.org/confluence/display/WW/S2-021, so this contribution will not be included in GHSA-prjv-jj26-wf8h. Thank you for your interest in GHSA-prjv-jj26-wf8h!

@github-actions github-actions bot deleted the sunSUNQ-GHSA-prjv-jj26-wf8h branch December 28, 2023 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants