(tick) These are the notes for the Struts version 6.6.0 distribution.

(tick) For prior notes in this release series, see Version Notes 6.4.0

Maven users

If you are a Maven user, you might want to get started using the Maven Archetype.

<dependency>
  <groupId>org.apache.struts</groupId>
  <artifactId>struts2-core</artifactId>
  <version>6.6.0</version>
</dependency>

You can also use Struts Archetype Catalog like below

mvn archetype:generate -DarchetypeCatalog=http://struts.apache.org/

Internal changes

Improved security by updating OGNL member access criteria, see WW-5417 and extending SecurityMemberAccess proxy detection to Hibernate proxies, seeĀ WW-5407.

We have also notably restricted the ability to invoke the static Enum method values() from OGNL expressions (WW-5418) due to its potential in escalating vulnerabilities. If you rely on this behaviour, you may re-expose such methods by wrapping it within a method on your Action class instead.

Bug

Improvement

Dependency

Issue Detail

Issue List

Other resources