• Post Reply Bookmark Topic Watch Topic
  • New Topic
programming forums Java Mobile Certification Databases Caching Books Engineering Micro Controllers OS Languages Paradigms IDEs Build Tools Frameworks Application Servers Open Source This Site Careers Other Pie Elite all forums
this forum made possible by our volunteer staff, including ...
Marshals:
  • Campbell Ritchie
  • Jeanne Boyarsky
  • Ron McLeod
  • Paul Clapham
  • Liutauras Vilda
Sheriffs:
  • paul wheaton
  • Rob Spoor
  • Devaka Cooray
Saloon Keepers:
  • Stephan van Hulst
  • Tim Holloway
  • Carey Brown
  • Frits Walraven
  • Tim Moores
Bartenders:
  • Mikalai Zaikin

Struts 2 Vulnerability Causes Shutdown of Canada Revenue Agency Website

 
Marshal
Posts: 4510
572
VSCode Eclipse IDE TypeScript Redhat MicroProfile Quarkus Java Linux
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
Canada Revenue Agency took its website offline over the weekend — a precautionary measure, officials said, while they dealt with an unspecified "internet vulnerability." ... we mean something called Apache Struts 2. It's a bunch of code that developers use to create web applications with the Java programming language.

This news is around a week old.  Heres are the story from CBC News

This is a report from the Security Now Podcast #603 - (timecode 39:21).  Some of the terminology isn't quite right, but still worth listening to.

Further information from NIST: Vulnerability Summary for CVE-2017-5638



 
Sheriff
Posts: 5555
326
IntelliJ IDE Python Java Linux
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
Thats's quite a zinger! Very brave, and sensible, of them to take the whole site offline to fix it. I'm sure a lot of other companies would be too scared to take their product offline.
reply
    Bookmark Topic Watch Topic
  • New Topic