Arbitrary Code Exectuion Affecting org.apache.struts:struts2-core package, versions [,2.2.3.1)
Threat Intelligence
Exploit Maturity
Mature
EPSS
18.65% (97th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHESTRUTS-30765
- published 17 Jun 2014
- disclosed 8 Jan 2012
- credit Unknown
Overview
org.apache.struts:struts2-core
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
References
CVSS Scores
version 3.1