URL Redirection to Untrusted Site Affecting org.apache.struts:struts2-core package, versions [2.0.0,2.3.15)


0.0
medium

Snyk CVSS

    Attack Complexity Low
    User Interaction Required

    Threat Intelligence

    Exploit Maturity Mature
    EPSS 97.19% (100th percentile)
Expand this section
NVD
5.4 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGAPACHESTRUTS-30049
  • published 14 Jul 2013
  • disclosed 14 Jul 2013
  • credit Takeshi Terada

Overview

org.apache.struts:struts2-core Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.