Struts2ã«ããã¦ã¯ã©ã¹ãã¼ãã¼ã®æä½ã許ãã¦ãã¾ãèå¼±æ§(CVE-2014-0094)ã«ã¤ãã¦å æ¥èª¿ã¹ãã®ã§ããããã®å¾ã®ã»ãã¥ãªãã£ãã³ãã®èª¿æ»ã«ããå½åã«æ¯ã¹ã¦å½±é¿ç¯å²ãå¤ãã£ã¦ãã¦ãããã¨ãããå度æ´çãããã¦ã¾ã¨ãã¾ããå°ããããæ å ±ã¯piyokangoãå ¨ã¦æ¤è¨¼ããããã§ã¯ãªãããã注æãã ãããã¾ãå½ç¶ãªããæªç¨ãããã¨ã¯å³ç¦ã§ãã Apache Software Foundationãããå½è©²èå¼±æ§æ å ±ã«é¢ããã¢ãã¦ã³ã¹ãåºã¾ããã 24 April 2014 - Struts up to 2.3.16.1: Zero-Day Exploit Mitigation S2-021 ã¯ã©ã¹ãã¼ãã¼ãæä½ãããèå¼±æ§ã®å½±é¿ç¯å² NTT-CERTãMBSDãLACã®èª¿æ»ã«ãã次ã®Strutsã®ãã¼ã¸ã§ã³ãå½±é¿ãåãããã¨ãå¤æãã¦ãã¾ããã¾ãBeanUtilsã使ã£ã¦ãªã¯ã¨ã¹ã
{{#tags}}- {{label}}
{{/tags}}