Release Notes

Complete Changelog for NES for Apache Struts

Struts

2.5.35 (NES) - December 23, 2024

Bug Fixes

This release patches the following:

  • File upload logic is flawed, and allows an attacker to enable paths with traversals (CVE-2024-53677).
    • com.herodevs.nes.apache.struts.struts2-core:2.5.33-struts2-2.5.35
  • Full Version: 2.5.33-struts2-2.5.35

2.5.34 (NES) - September 5, 2024

Notes

  • This release originates from the open-source Struts project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from Struts version 2.5.33.
  • Full Version: 2.5.33-struts2-2.5.34

Struts Parent

14.0.1 (NES) - September 5, 2024

Notes

  • This release originates from the open-source Struts Master forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from Struts Master 14.
  • Full Version: 14.0.0-struts-master-14.0.1