|
|
Subscribe / Log in / New account

Apache Struts Statement on Equifax Security Breach

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 13:39 UTC (Mon) by pboddie (guest, #50784)
In reply to: Apache Struts Statement on Equifax Security Breach by mattdm
Parent article: Apache Struts Statement on Equifax Security Breach

Struts was the in-vogue technology back when I last had Java as the focus of my full-time job (as opposed to taking over the maintenance of colleagues' projects), which was 2005 or thereabouts. Managers would seemingly gladly throw money at shareware-quality add-ons to "help" with Struts application development (in Eclipse, of course) rather than pay for well-maintained Free Software, such was the nature of the Java ecosystem at that point.

Given that other technologies stole Java's thunder in many regards, and that things like Maven didn't come along (or not with any force) until later, and that inertia would prevent the introduction of update strategies in environments where things like Struts have been used, I wouldn't want to think about how many applications there are that are vulnerable. It also doesn't help that things like Tomcat and Jetty are regulars on the vulnerability calendar, either.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds