These are the notes for the Struts 18.104.22.168 distribution.
For prior notes in this release series, see Version Notes 22.214.171.124
- If you are a Maven user, you might want to get started using the Maven Archetype.
- Another quick-start entry point is the blank application. Rename and deploy the WAR as a starting point for your own development.
You can also use Struts Archetype Catalog like below
mvn archetype:generate -DarchetypeCatalog=http://struts.apache.org/126.96.36.199/
<name>ASF Nexus Staging</name>
- Default acceptedParamNames were further updated to more restrictive values to solve security vulnerabilities in ParameterInterceptor.
Also a new method was added to ValueStack called setParameter to prevent remote code execution through the evaluation of parameter names.