Are you an Apache Struts user who follows security advisories? If so, they may be giving you a false sense of security. . Security researchers have reviewed security advisories for Apache Struts and found that two dozen of them inaccurately listed affected versions for the open-source development framework. The advisories have since been updated to reflect vulnerabilities in an additional 61 unique versions of Struts that were affected by at least one previously disclosed vulnerability but left off the security advisories for those vulnerabilities. The extensive analysis was done by the Black Duck Security Research (BDSR) team of Synopsys’ Cybersecurity Research Center (CyRC), which investigated 115 distinct releases for Apache Struts and correlated those releases against 57 existing Apache Struts Security Advisories covering 64 vulnerabilities. The link for this article located at Naked Security is no longer available. . Experts discovered 67 variations of Nginx not mentioned in security bulletins, prompting worries about their security.. Apache Struts Security, advisory oversight, software vulnerabilities, version discrepancies. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.