Lucene search

K
osvGoogleOSV:GHSA-8FX9-5HX8-CRHM
HistoryOct 16, 2018 - 7:35 p.m.

Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal

2018-10-1619:35:40
Google
osv.dev
30

8.9 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%

In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.