Child pages
  • Version Notes 2.3.33
Skip to end of metadata
Go to start of metadata

(tick) These are the notes for the Struts 2.3.33 distribution.

(tick) For prior notes in this release series, see Version Notes 2.3.32

  • If you are a Maven user, you might want to get started using the Maven Archetype.
  • Another quick-start entry point is the blank application. Rename and deploy the WAR as a starting point for your own development.
  • There is huge number of examples you can also use as a starting point for you application here
Maven Dependency

You can also use Struts Archetype Catalog like below

Struts Archetype Catalog
Staging Repository

Internal Changes

  • (warning) Possible RCE in the Struts Showcase app in the Struts 1 plugin example in Struts 2.3.x series, see S2-048
  • (warning) A DoS attack is available for Spring secured actions, see S2-049
  • Bug

    • [WW-4735] - EmailValidator does not accept new domain suffixes
    • [WW-4770] - Revision number still missing from dojo.js and dojo.js.uncompressed.js
    • [WW-4802] - Strange Behavior Parsing Action Requests

    Improvement

    • [WW-4805] - At least a DoS attack is available for Spring secured actions

 

This release contains fixes related to S2-048 and S2-049, please read them carefully!

Issue Detail

Issue List

Other resources



  • No labels