Security Advisory:LPS-46552 - Struts 1 Classloader manipulationSecurity Advisory:LPS-46552 - Struts 1 Classloader manipulationhttps://liferay.dev/en/c/message_boards/find_thread?p_l_id=119785333&threadId=375733552024-03-29T07:17:33Z2024-03-29T07:17:33ZSecurity Advisory:LPS-46552 - Struts 1 Classloader manipulationJames Falknerhttps://liferay.dev/en/c/message_boards/find_message?p_l_id=119785333&messageId=375733542014-05-07T22:42:06Z2014-05-07T22:42:06ZThe following security advisory has been announced for Liferay Portal 6.2 CE GA2 (6.2.1):<ul> <li>CST-SA: LPS-46552 Struts 1 Classloader manipulation</li></ul>A zero-day security vulnerability in the ActionForms object in Struts 1.x allows remote attackers to manipulate the class loader. In some environments, this may allow attackers to execute arbitrary code. While Liferay Portal utilizes Struts 1.x, <strong>Liferay Portal is *NOT* susceptible</strong> to this vulnerability because Liferay Portal does not uses Struts 1.x's ActionForm for any out of the box functionality. However, sites using Liferay Portal may be vulnerable if:<ul> <li>Custom Struts 1.x plugin portlets have been deployed to the environment AND </li><li>The custom Struts 1.x plugin portlet uses ActionForm.</li></ul><a href="https://www.liferay.com/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/cst-sa-lps-46552-struts-1-classloader-manipulation">More information about the vulnerability</a>. Liferay Portal CE users are strongly advised to keep abreast of all new security advisories and apply associated fixes or workarounds to your Liferay deployments. To be notified of future releases, be sure to subscribe to the <a href="https://www.liferay.com/community/forums/-/message_boards/category/14757379">this forum</a> and follow the <a href="https://www.liferay.com/community/security-team/known-vulnerabilities">known vulnerabilities list</a> (e.g.