[GHSA-vrwc-qjmw-5rjm] ClassLoader manipulation in Apache Struts
Updates
- Affected products
- References
Comments
Add a patch https://github.com/apache/struts/commit/74e26830d2849a84729b33497f729e0f033dc147, of which the commit message claims Adds additional pattern to prevent access to getClass method
Hey @MarkLee131, it looks like this commit is tagged for 2.5.x where the advisory calls out 2.3.16.2 as the fixed version.
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.