Lucene search

K
osvGoogleOSV:GHSA-44HV-JJX7-QFJG
HistoryMay 14, 2022 - 12:54 a.m.

Path Traversal in Apache Struts

2022-05-1400:54:13
Google
osv.dev
24

0.02 Low

EPSS

Percentile

89.0%

In Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side. This vulnerability is only exploitable when using the Struts 2 Convention plugin in conjunction with Apache Struts.

0.02 Low

EPSS

Percentile

89.0%