Uploaded image for project: 'Struts 2'
  1. Struts 2
  2. WW-4917

Clarification on security status and support for Struts 2.3

    XMLWordPrintableJSON

Details

    • Task
    • Status: Reopened
    • Minor
    • Resolution: Unresolved
    • 2.3.34
    • None
    • Documentation

    Description

      Hi
       
      Can you kindly provide clarity as to the exact status of the 2.3 series in terms of ongoing support and security status.
       
       
      On the Struts web page https://struts.apache.org/
       
      I found the statement:
       
      "It's the latest release of Struts 2.3.x which contains the latest security fixes, read more in Announcement or in Version notes"
       
      Yet, on the page at https://struts.apache.org/releases.html it is stated that :
       

      "Prior Releases

      As a courtesy, we retain archival copies of the website for releases that initially were considered "General Availability" but which has been reclassified as "Not recommended" since they contain security issues
      "
      And version 2.3.34 is listed here.
       
       
      Lastly - I find no EOL announcement for 2.3.x
       
      So in summary the question is:
       
      1 Is the 2.3 series EOL?
      2 Does 2.3.34 contain any known security bugs?
       
       
      Thanking you in advance 
       
      Richard

      Attachments

        Activity

          People

            lukaszlenart Lukasz Lenart
            RichardWHTaylor Richard Taylor
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: