Uploaded image for project: 'Chukwa (retired)'
  1. Chukwa (retired)
  2. CHUKWA-822

Update struts version to avoid security hole

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • None
    • None
    • None

    Description

      Apache Struts was imported into Chukwa as dependency by velocity-tools. Struts has a high severity security defect, which is described in CVE-2017-9805. Struts 2.13 patched this security defect, and Chukwa should consider upgradeing to the latest Apache Struts.

      Attachments

        1. CHUKWA-822.patch
          1 kB
          Eric Yang

        Activity

          People

            Unassigned Unassigned
            eyang Eric Yang
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: