Uploaded image for project: 'Struts 2'
  1. Struts 2
  2. WW-4917

Clarification on security status and support for Struts 2.3

    XMLWordPrintableJSON

    Details

    • Type: Task
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 2.3.34
    • Fix Version/s: 2.5.x
    • Component/s: Documentation
    • Labels:

      Description

      Hi
       
      Can you kindly provide clarity as to the exact status of the 2.3 series in terms of ongoing support and security status.
       
       
      On the Struts web page https://struts.apache.org/
       
      I found the statement:
       
      "It's the latest release of Struts 2.3.x which contains the latest security fixes, read more in Announcement or in Version notes"
       
      Yet, on the page at https://struts.apache.org/releases.html it is stated that :
       

      "Prior Releases

      As a courtesy, we retain archival copies of the website for releases that initially were considered "General Availability" but which has been reclassified as "Not recommended" since they contain security issues
      "
      And version 2.3.34 is listed here.
       
       
      Lastly - I find no EOL announcement for 2.3.x
       
      So in summary the question is:
       
      1 Is the 2.3 series EOL?
      2 Does 2.3.34 contain any known security bugs?
       
       
      Thanking you in advance 
       
      Richard

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              RichardWHTaylor Richard Taylor
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated: