Lucene search

K
osvGoogleOSV:GHSA-2PPP-XJ34-VVF7
HistoryMay 04, 2022 - 12:29 a.m.

Apache Struts's CookieInterceptor component does not use the parameter-name whitelist

2022-05-0400:29:43
Google
osv.dev
5

8 High

AI Score

Confidence

Low

0.962 High

EPSS

Percentile

99.5%

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

8 High

AI Score

Confidence

Low

0.962 High

EPSS

Percentile

99.5%