org.apache.struts.xwork:xwork-core@2.3.28 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.struts.xwork:xwork-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Execution

org.apache.struts.xwork:xwork-core Affected versions of the package are vulnerable to Remote code Execution. The Apache Struts frameworks when forced, performs double evaluation of attributes' values assigned to certain tags so it is possible to pass in a value that will be evaluated again when a tag's attributes will be rendered.

[2.2.1,2.3.28.1]
  • H
Access Restriction Bypass

org.apache.struts.xwork:xwork-core is a generic command pattern framework. It forms the core of Struts 2.

Affected versions of this package are vulnerable to Access Restriction Bypass. It allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

[2.3.20,2.3.28.1]
  • M
Regular Expression Denial of Service (ReDoS)

org.apache.struts.xwork:xwork-core is a generic command pattern framework. It forms the core of Struts 2.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). The URLValidator class allows remote attackers to cause a denial of service via a null value for a URL field.

How to fix Regular Expression Denial of Service (ReDoS)?

Upgrade org.apache.struts.xwork:xwork-core to version 2.3.29 or higher.

[2.3.20,2.3.29)
  • H
Command Injection

org.apache.struts.xwork:xwork-core is a generic command pattern framework. It forms the core of Struts 2.

Affected versions of this package are vulnerable to Command Injection. When Dynamic Method Invocation was enabled, a remote attackers could execute arbitrary code via the prefix method, related to chained expressions.

How to fix Command Injection?

Upgrade org.apache.struts.xwork:xwork-core to version 2.3.20.2, 2.3.24.2, 2.3.28.1 or higher.

[2.0.0,2.3.20.2) [2.3.24,2.3.24.2) [2.3.28,2.3.28.1)