Unrestricted Upload of File with Dangerous Type Affecting org.apache.struts:struts2-core package, versions [,2.5)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.4% (74th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Unrestricted Upload of File with Dangerous Type vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHESTRUTS-609765
  • published4 Sept 2020
  • disclosed5 Dec 2019
  • creditUnknown

Introduced: 5 Dec 2019

CVE-2012-1592  (opens in a new tab)
CWE-434  (opens in a new tab)

How to fix?

Upgrade org.apache.struts:struts2-core to version 2.5 or higher.

Overview

org.apache.struts:struts2-core is a popular open-source framework for developing web applications in the Java programming language.

Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type. A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.

CVSS Scores

version 3.1