CVE-2018-11776 struts exploit | impact to DHIS 2?

DHIS2 Dev Team,

Can you comment on the recent
CVE-2018-11776
vulnerability in Struts 2.0 being contained in DHIS 2 (specially Version 2.25). I did not see any recent threads about this on DHIS 2 DEV or USERS mailing lists.

Additional details on the vulnerability (and patch from Apache) is available here:
https://krebsonsecurity.com/2018/08/experts-urge-rapid-patching-of-struts-bug/?_ke=eyJrbF9lbWFpbCI6ICJtYXR0aGV3LmRvbGxhY2tlckBnbWFpbC5jb20iLCAia2xfY29tcGFueV9pZCI6ICJlN1lDM3UifQ%3D%3D

Many thanks in advance,

-Stephen

Hi Stephan

Let me include Lars reply from a thread where we were discussing this.

“”"

we did an assessment of this last week and concluded that we are not affected by this vulnerability. This due to the two conditions mentioned (use of namespaces and alwaysSelectFullNamespace config property).

That said we have patched all versions from 2.28 and later and you can fetch the new builds from dhis2.org/downloads.

“”"

···

Morten Olav Hansen

Senior Engineer, DHIS 2

Team Integration Lead

University of Oslo

http://www.dhis2.org

Hi, Morten.

Apologies for the late reply. Thank you for confirming the vulnerability is not present.

Much appreciated.

-Stephen

···

Hi Stephan

Let me include Lars reply from a thread where we were discussing this.

“”"

we did an assessment of this last week and concluded that we are not affected by this vulnerability. This due to the two conditions mentioned (use of namespaces and alwaysSelectFullNamespace config property).

That said we have patched all versions from 2.28 and later and you can fetch the new builds from dhis2.org/downloads.

“”"

Morten Olav Hansen

Senior Engineer, DHIS 2

Team Integration Lead

University of Oslo

[http://www.dhis2.org

](http://www.dhis2.org)

On Sat, Sep 8, 2018 at 3:19 AM Stephen Macauley Stephen.Macauley@inductivehealth.com wrote:

DHIS2 Dev Team,

Can you comment on the recent CVE-2018-11776 vulnerability in Struts 2.0 being contained in DHIS 2 (specially Version 2.25). I did not see any recent threads about this on DHIS 2 DEV or USERS mailing lists.

Additional details on the vulnerability (and patch from Apache) is available here:
https://krebsonsecurity.com/2018/08/experts-urge-rapid-patching-of-struts-bug/?_ke=eyJrbF9lbWFpbCI6ICJtYXR0aGV3LmRvbGxhY2tlckBnbWFpbC5jb20iLCAia2xfY29tcGFueV9pZCI6ICJlN1lDM3UifQ%3D%3D

Many thanks in advance,

-Stephen


Mailing list: https://launchpad.net/~dhis2-devs

Post to : dhis2-devs@lists.launchpad.net

Unsubscribe : https://launchpad.net/~dhis2-devs

More help : https://help.launchpad.net/ListHelp