The Apache Foundation urged developers to update a key component of the framework in order to patch the flaw in an alert posted Monday. Projects using Struts 2.3.36 and prior are affected, Apache said, because of a vulnerable commons-fileupload library.
Read full news article on Cyberscoop