Security Vulnerabilities fixed in Apache Struts S2-008

description-logoDescription

To prevent attackers calling arbitrary methods within parameters the flagxwork.MethodAccessor.denyMethodExecutionis set totrueand theSecurityMemberAccessfieldallowStaticMethodAccessis set tofalseby default. Also, to prevent access to context variables an improved character whitelist for parameter names is applied in theParameterInterceptorsince Struts 2.2.1.1:

affected-products-logoAffected Applications

Apache Struts