VDB
Sign up
CRITICAL9.8

GHSA-47qp-8v9g-39hp

Code injection in Apache Struts

Quick fix

GHSA-47qp-8v9g-39hp — org.apache.struts:struts2-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.3.15.1</version> for org.apache.struts:struts2-core

Details

The Struts 2 DefaultActionMapper supports a method for short-circuit navigation state changes by prefixing parameters with "action:" or "redirect:", followed by a desired navigational target expression. This mechanism was intended to help with attaching navigational information to buttons within forms.

In Struts 2 before 2.3.15.1 the information following "action:", "redirect:" or "redirectAction:" is not properly sanitized. Since said information will be evaluated as OGNL expression against the value stack, this introduces the possibility to inject server side code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.struts:struts2-core
Introduced in: 0Fixed in: 2.3.15.1
Fix# pom.xml: bump <version>2.3.15.1</version> for org.apache.struts:struts2-core

References