Fixed
Details
Assignee
Himabindu AkkinepalliHimabindu AkkinepalliReporter
Himabindu AkkinepalliHimabindu AkkinepalliComplexity
LowAffects versions
Priority
Should
Details
Details
Assignee
Himabindu Akkinepalli
Himabindu AkkinepalliReporter
Himabindu Akkinepalli
Himabindu AkkinepalliComplexity
Low
Affects versions
Priority
Created May 10, 2022 at 11:24 AM
Updated May 31, 2022 at 3:55 PM
Resolved May 31, 2022 at 3:55 PM
There is a vulnerability reported on struts-core-1.3.8.jar. And this is coming as part of the org.apache.velocity.velocitytools dependency.
Steps followed to mitigate the vulnerability:
Manually removed the struts-core-1.3.8.jar from the openmrs env.
Restarted the openmrs service.
Application started working fine without any issues, and we tested the basic flows. Everything looks fine.
Raised talk thread for the same.
https://talk.openmrs.org/t/struts-core-1-3-8-security-vulnerability-in-openmrs-core/36523
PR link to exclude the struts-core.1.3.8.jar from the pom.xml
https://github.com/openmrs/openmrs-core/pull/4083