org.apache.struts:struts-extras@1.3.10 vulnerabilities

  • latest version

    1.3.10

  • first published

    19 years ago

  • latest version published

    16 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.struts:struts-extras package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Output Neutralization for Logs

    Affected versions of this package are vulnerable to Improper Output Neutralization for Logs via the LookupDispatchAction function. An attacker can manipulate log output by submitting specially crafted input, causing parts of the log message to appear as separate log lines and potentially misleading log consumers by injecting untrusted data into the logs.

    Note: This package is retired, so no fix is expected.

    How to fix Improper Output Neutralization for Logs?

    There is no fixed version for org.apache.struts:struts-extras.

    [0,)