org.apache.struts:struts2-core vulnerabilities

  • latest version

    7.0.3

  • latest non vulnerable version

  • first published

    18 years ago

  • latest version published

    6 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.struts:struts2-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Remote Code Execution (RCE)

    [,7.0.0)
    • M
    Directory Traversal

    [2.0.0,2.0.12)[2.1.0,2.1.6)
    • M
    Cross-site Scripting (XSS)

    [2.0.0,2.0.11.1)
    • C
    Remote Code Execution (RCE)

    [,2.5.33)[6.0.0,6.3.0.2)
    • M
    Denial of Service (DoS)

    [,2.5.32)[6.0.0,6.1.2.2)[6.2.0,6.3.0.1)
    • H
    Allocation of Resources Without Limits or Throttling

    [2.0.0,2.5.31)[6.0.0,6.1.2.1)
    • M
    Allocation of Resources Without Limits or Throttling

    [2.0.0,2.5.31)[6.1.2,6.1.2.1)
    • H
    Remote Code Execution (RCE)

    [2.0.0,2.5.30)
    • C
    Remote Code Execution (RCE)

    [2.0.0,2.5.26)
    • H
    Unrestricted Upload of File with Dangerous Type

    [,2.5)
    • H
    Denial of Service (DoS)

    [2.0.0,2.5.22)
    • C
    Remote Code Execution (RCE)

    [2.0.0,2.5.22)
    • H
    Remote Code Execution (RCE)

    [2.3.0,2.3.35)[2.5.0,2.5.17)
    • M
    Denial of Service (DoS)

    [2.5-BETA1,2.5.14.1)
    • H
    Denial of Service (DoS)

    [2.3.7,2.3.34)[2.5,2.5.13)
    • H
    Denial of Service (DoS)

    [2.3.7,2.3.34)[2.5,2.5.13)
    • H
    Denial of Service (DoS)

    [2.3.7,2.3.33)[2.5,2.5.12)
    • M
    Denial of Service (DoS)

    [2.5,2.5.12)
    • H
    Arbitrary Command Execution

    [,2.3.34)[2.4,2.5.13)
    • C
    Arbitrary Code Execution

    [,2.3.34)[2.4,2.5.12)
    • C
    Arbitrary Code Execution

    [2.3.7,2.3.32)[2.5.0,2.5.10.1)
    • M
    Arbitrary OGNL Statement Execution

    [2.0.0,2.2.1)
    • M
    Denial of Service (DoS)

    [2.5,2.5.13)
    • C
    Directory Traversal

    [2.3.20,2.3.31)
    • C
    Improper Action Name Cleanup

    [2.0.0,2.3.29)[2.5,2.5.1)
    • H
    Access Restriction Bypass

    [2.3.20,2.3.29)
    • H
    Access Restriction Bypass

    [2.3.20,2.3.29)
    • M
    Regular Expression Denial of Service (ReDoS)

    [2.3.20,2.3.29)[2.5,2.5.1)
    • H
    Cross-site Request Forgery (CSRF)

    [2.3.20,2.3.29)
    • C
    Arbitrary Command Execution

    [2,2.3.20.2)[2.3.24,2.3.24.3)[2.3.28,2.3.28.1)
    • H
    Command Injection

    [2.0.0,2.3.20.2)[2.3.24,2.3.24.2)[2.3.28,2.3.28.1)
    • C
    Arbitrary Code Execution

    [2,2.3.20.2)[2.3.24,2.3.24.2)[2.3.28,2.3.28.1)
    • M
    Cross-site Scripting (XSS)

    [,2.3.28)
    • L
    Cross-site Scripting (XSS)

    [2,2.3.20)
    • M
    Cross-site Scripting (XSS)

    [2.0.0,2.3.20)
    • H
    Manipulation of Struts' internals

    [2.0.0,2.3.24.1)
    • M
    Cross-site Request Forgery (CSRF)

    [2.0.0,2.3.20)
    • H
    Arbitrary Code Exectuion

    [,2.2.3.1)
    • M
    Arbitrary File Overwrite

    [,2.3.1.1)
    • H
    Arbitrary Command Execution

    [,2.3.1.1)
    • M
    Arbitrary Code Execution

    [,2.3.1.1)
    • C
    Improper Input Validation

    [2.0.0,2.2.3.1)
    • H
    Arbitrary Code Execution

    [2.0.0,2.3.14.3)
    • M
    Classloader manipulation via CookieInterceptor

    [2.0.0,2.3.20)
    • H
    Arbitrary Code Execution

    [2.0.0,2.3.16.2)
    • M
    ClassLoader Manipulation via ParametersInterceptor

    [2,2.3.16.1)
    • M
    Access Restriction Bypass

    [,2.3.1.2)
    • M
    Bypass Access Controls

    [2.0.0,2.3.15.3)
    • C
    Dynamic Method Executions

    [2.0.0,2.3.15.2)
    • H
    Remote Command Execution

    [2,2.3.15)
    • M
    URL Redirection to Untrusted Site

    [2.0.0,2.3.15)
    • H
    Arbitrary Code Injection

    [2.0.0,2.3.14.3)
    • H
    Arbitrary Code Injection

    [2,2.3.14.1)
    • H
    Arbitrary Code Injection

    [2,2.3.14.2)
    • H
    Arbitrary Code Injection

    [2.0.0,2.3.14.1)
    • M
    Cross-site Request Forgery (CSRF)

    [2.0.0,2.3.4.1)
    • M
    Remote code execution

    [2,2.3.1.1)
    • L
    Cross-site Scripting (XSS)

    [2.0.0,2.2.3)
    • M
    Remote Command Execution

    [2,2.1.8.1)

    Package versions

    103 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    7.0.317 Feb, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    7.0.011 Dec, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.7.420 Feb, 2025
    • 1
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.7.017 Nov, 2024
    • 1
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.6.15 Oct, 2024
    • 1
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.6.020 Jul, 2024
    • 1
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.4.07 Apr, 2024
    • 1
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.3.0.25 Dec, 2023
    • 1
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.3.0.111 Sep, 2023
    • 2
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.3.01 Sep, 2023
    • 2
      C
    • 0
      H
    • 1
      M
    • 0
      L