Lucene search

K
osvGoogleOSV:GHSA-737W-MH58-CXJP
HistoryMay 14, 2022 - 12:54 a.m.

Arbitrary code execution in Apache Struts

2022-05-1400:54:15
Google
osv.dev
10

0.019 Low

EPSS

Percentile

88.4%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.