Struts security strings search in struts.xml and API

This list of keywords directly related to the struts security issues will help us to use a search tool (such as drek or Graudit) to locate and to identify the issue; take a look at the following table:

Struts security

Keyword search in bold

Development mode


Review tips: The suggested value should be false in struts.xml.

Dynamic method invocation


Review tips: The suggested value should be false in struts.xml.

OGNL static method access


Review tips: The suggested value should be false in struts.xml.

File upload




Review tips

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.