FYI…

Apache Struts 2.5.14.1
- https://cwiki.apache.org/confluence/display/WW/S2-054
Dec 01, 2017
> https://cwiki.apache.org/confluence/pages/diffpagesbyversion.action?pageId=74688631&selectedPageVersions=9&selectedPageVersions=10
Recommendation: Upgrade to Struts 2.5.14.1
Affected Software: Struts 2.5 - Struts 2.5.14

- https://www.securitytracker.com/id/1039946
CVE Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-15707
Dec 1 2017
Impact: Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2.5 - 2.5.14
Description: A vulnerability was reported in Apache Struts. A remote user can cause denial of service conditions on the target system.
A remote user can send specially crafted JSON data to trigger a flaw in the REST Plugin's default JSON-lib handler and cause denial of service conditions.
Impact: A remote user can cause denial of service conditions.
Solution: The vendor has issued a fix (2.5.14.1)…

>> https://cwiki.apache.org/confluence/pages/viewpreviousversions.action?pageId=74688649

Apache Struts 2 Documentation
Apache Struts Version Notes 2.5.14.1
>> https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.5.14.1

- https://cwiki.apache.org/confluence/display/WW/S2-055
Dec 01, 2017
> https://cwiki.apache.org/confluence/pages/diffpagesbyversion.action?pageId=74688649&selectedPageVersions=3&selectedPageVersions=4
Recommendation: Upgrade to Struts 2.5.14.1

- https://www.securitytracker.com/id/1039947
CVE Reference: CVE-2017-7525
Dec 1 2017
Impact: Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2.5 - 2.5.14
Description: A vulnerability was reported in Apache Struts. The impact was not specified.
A remote user can send specially crafted data to trigger a deserialization error in the jackson-databind component. The readValue() method of the ObjectMapper is affected…
[Editor's note: The vendor advisory does not specify the impact. However, because the deserialization vulnerability in the jackson-databind component can lead to code execution in other applications of the component, this Alert has been categorized as a state error with code execution impact.]
Solution: The vendor has issued a fix (2.5.14.1)…
___

> https://www.us-cert.gov/ncas/current-activity/2017/12/04/Apache-Software-Foundation-Releases-Security-Updates
Dec 04, 2017 - "… upgrade to Struts 2.5.14.1."

> https://cwiki.apache.org/confluence/display/WW/S2-054

> https://cwiki.apache.org/confluence/display/WW/S2-055
 

:ph34r: :ph34r: