Apache Struts and Moodle

Apache Struts and Moodle

by Rick Sparrow -
Number of replies: 4

Hi there... Can anyone tell me if Moodle is impacted by the recently announced Apache Struts vulnerability? If so, is there an update for Moodle that fixes this? I'm not a dev by any means but I have Googled and can't find a whole lot on Moodle and Apache Struts, so I'm really not sure. When i go to Admin --> Server --> PHP info, I can't find anything referring to Struts.... If Moodle does use Apache Struts, how would I determine the version installed?


Thanks in advance,

Rick

Average of ratings: -
In reply to Rick Sparrow

Re: Apache Struts and Moodle

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

Unless I'm mistaken... Struts is a Java web framework.

Moodle is written in PHP, so you don't need to worry about Struts issues. 

In reply to Howard Miller

Re: Apache Struts and Moodle

by Rick Sparrow -
Great, thanks for the clarification.


In reply to Rick Sparrow

Re: Apache Struts and Moodle

by Marcus Green -
Picture of Core developers Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers

Howard is correct this issue does not affect Moodle. 

Detailed explanation for the geek inclined.... Apache Struts is a Java framework, Moodle contains no Java or indeed Apache Struts. Moodle contains quite a bit of JavaScript but Javascript is only related to Java in that some misguided person changed the name of a thing called LiveScript to Javascript because Java was fasionable. It has caused confusion ever since. This was discussed recently on slashdot where they put up a confusing (possibly click baity headline)

https://apache.slashdot.org/story/17/03/10/0328221/apache-servers-under-attack-through-easily-exploitable-struts-2-flaw

Average of ratings: Useful (1)
In reply to Marcus Green

Re: Apache Struts and Moodle

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

Apparently JavaScript is now fashionable. I really have no idea why evil