Lucene search

K
osvGoogleOSV:GHSA-876P-4WGC-75RX
HistoryMay 14, 2022 - 12:52 a.m.

Apache Struts RCE Vulnerability

2022-05-1400:52:12
Google
osv.dev
8

7.7 High

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

88.0%

Apache Struts 2.x before 2.3.20.3, 2.3.24.3, and 2.3.28 allows remote attackers to execute arbitrary code via a %{} sequence in a tag attribute, aka forced double OGNL evaluation.

7.7 High

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

88.0%