com.opensymphony:xwork@2.0.5 vulnerabilities
XWork is an command-pattern framework that is used to power WebWork as well as other applications. XWork provides an Inversion of Control container, a powerful expression language, data type conversion, validation, and pluggable configuration.
-
latest version
2.1.3
-
latest non vulnerable version
-
first published
16 years ago
-
latest version published
14 years ago
-
licenses detected
- [0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the com.opensymphony:xwork package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
com.opensymphony:xwork is a generic command pattern framework. It forms the core of Struts 2. Affected versions of this package are vulnerable to Arbitrary OGNL Statement Execution. How to fix Arbitrary OGNL Statement Execution? Upgrade |
[2.0.0,2.0.6)
[2.1.0,2.1.2)
|