Re: Dependencies with known CVEs in struts2-core 7.0.3

Lukasz Lenart <[email protected]> Thu, 25 Sep 2025 10:07:09 +0200
Newsgroups gmane.comp.jakarta.struts.devel
Message-ID <CAMopvkPK_p9FRtkA7p2inLe5QbX2S827mr+hWc9tZ+Fj3=PdsQ@mail.gmail.com>
czw., 25 wrz 2025 o 09:59 Rahul Kumar <[email protected]> napisaƂ(a):

> Hi all,
>

Hi, you must subscribe to the mailing list to get notifications


> I noticed that struts2-core 7.0.3 still ships with some dependencies that
> contain known vulnerabilities. From what I can see, the upstream projects
> have already addressed these CVEs in their latest releases.
>
> Are there plans to update these dependencies in an upcoming Struts
> release? If helpful, I can share the specific dependencies and CVEs I found.
>

Dependabot is taking care of that, here is a list of updates in
incoming 7.1.0 version
https://github.com/apache/struts/releases/tag/STRUTS_7_1_0

[image: image.png]
>

Images are not allowed

Cheers
Lukasz