ClassLoader Manipulation via ParametersInterceptor Affecting org.apache.struts:struts2-core package, versions [2,2.3.16.1)
Threat Intelligence
Exploit Maturity
Mature
EPSS
97.04% (100th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHESTRUTS-30053
- published 6 Mar 2014
- disclosed 6 Mar 2014
- credit Unknown
Overview
org.apache.struts:struts2-core
The ParametersInterceptor in Apache Struts before 2.3.16.1 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
CVSS Scores
version 3.1