Version 220.127.116.11 of the open source Apache Struts web application framework was recently released.
"The update closes critical holes in Struts 2, fixing four old and well known security vulnerabilities that could be exploited by an attacker to circumvent restrictions by using dynamic method invocation (DMI) to inject and execute malicious Java code," The H Security reports.
"Versions 2.1.0 to 2.3.1 of Struts are affected; upgrading to 18.104.22.168 corrects the issues," the article states.
Go to "Apache Struts update closes critical holes" to read the details.
For regular security news updates, follow eSecurityPlanet on Twitter: @eSecurityP.