Apache Struts CVE-2024-53677

Kris Massey shared this question 3 days ago
Completed

We have become aware of CVE-2024-53677, and wanted to get some further detail on the version of struts used in different versions of Yellowfin to see if the current version we are running are exposed. Is this information published anywhere?

Replies (3)

photo
1

Hello Kris Massey,

My name is Nishant Garg from the Yellowfin Technical Support Team. We have received your support request, and I will be your primary contact on the following ticket:

Ticket Number: #31742
Case Title: Apache Struts CVE-2024-53677

Next Steps and Workarounds:


This is to inform you that Yellowfin does not use Struts, it was removed from our product as at version 8.0.4. If you are detecting this on your system, then it is likely installed by another product.

I hope this helps.


Sincerely,

Nishant Garg

Yellowfin Technical Support Engineer

photo
1

Hi Nishant,


Thanks for the speedy reply and confirmation.


Thanks

Kris

photo
1

Hello Kris Massey

I am glad to hear the issue was resolved. If you have any other issue please contact us again by opening up a new ticket and we will provide additional support.

We value the customer experience and feedback and would like to understand your experience from our recent interaction. Please spare a moment to respond to the quick survey that was sent; we assure you, it won’t take much time to answer!

Your valuable feedback will help us serve you better in the future. Thank you for taking the time.


Thank you,

Nishant Garg

Yellowfin Technical Support

Leave a Comment
 
Attach a file