<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
<div>I was asked to determine whether Shibboleth uses Struts 2 with respect to this advisory about a vulnerability in Struts2:</div>
<div><br>
</div>
<a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2251" target="_blank" style="font-family: 'Times New Roman'; font-size: 16px; ">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2251</a>
<div><br>
</div>
<div>I didn't see this vulnerability listed on the Shibboleth website but again, asked to make sure.</div>
<div><br>
</div>
<div>Thanks,</div>
<div><br>
</div>
<div>Joy</div>
</body>
</html>