Arbitrary Code Execution Affecting com.opensymphony:xwork-core Open this link in a new tab package, versions [2.1.4,2.1.6)


0.0
critical
  • Exploit Maturity

    Mature

  • Attack Complexity

    Low

  • Confidentiality

    High

  • Integrity

    High

  • Availability

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    SNYK-JAVA-COMOPENSYMPHONY-30324

  • published

    22 Jan 2012

  • disclosed

    22 Jan 2012

  • credit

    Meder Kydyraliev

Overview

com.opensymphony:xwork-core is an command-pattern framework that is used to power WebWork as well as other applications. XWork provides an Inversion of Control container, a powerful expression language, data type conversion, validation, and pluggable configuration.

OGNL provides, among other features, extensive expression evaluation capabilities. The vulnerability allows a malicious user to bypass all the protections (regex pattern, deny method invocation) built into the ParametersInterceptor, thus being able to inject a malicious expression in any exposed string variable for further evaluation.