Re: [ANN] Struts 2.3.16.1 GA release available - security fix
Lukasz Lenart <[email protected]>
| Newsgroups | gmane.comp.security.full-disclosure,gmane.comp.jakarta.lucene.net.user,gmane.comp.apache.incubator.bigtop.devel |
|---|---|
| Message-ID | <CAMopvkPO-vUYXr2HkaFakYY3+9jfSnN8QV2dTg_oTc6EL9z38w__24402.9694040821$1394149799$gmane$org@mail.gmail.com> |
No, rather no. You gain access to ClassLoader. 2014-03-06 16:43 GMT+01:00 Tim <[email protected]>: > >> This release includes important security fixes: >> - S2-020 - ClassLoader manipulation via request parameters > > What is the ultimate impact of this manipulation? Another RCE bug? > > tim _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/