Updates released on Wednesday for the Apache Struts 2 open source development framework address a critical vulnerability that can be exploited for remote code execution.
The flaw, tracked as CVE-2018-11776, affects Struts 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and possibly unsupported versions of the framework.
http://feedproxy.google.com/~r/Securityweek/~3/OKcyhqelPSw/critical-apache-struts-2-flaw-allows-remote-code-execution










