VDB
Sign up
HIGH8.1

GHSA-cr6j-3jp9-rw65

Apache Struts vulnerable to remote command execution (RCE) due to improper input validation

Quick fix

GHSA-cr6j-3jp9-rw65 — org.apache.struts:struts2-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.3.35</version> for org.apache.struts:struts2-core

Details

Apache Struts contains a Remote Code Execution when using results with no namespace and it's upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set, and it's upper actions have no or wildcard namespace.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.struts:struts2-core
Introduced in: 2.0.4Fixed in: 2.3.35
Fix# pom.xml: bump <version>2.3.35</version> for org.apache.struts:struts2-core
Maven/org.apache.struts:struts2-core
Introduced in: 2.5Fixed in: 2.5.17
Fix# pom.xml: bump <version>2.5.17</version> for org.apache.struts:struts2-core

References