Lucene search

K
osvGoogleOSV:GHSA-8M5Q-CRQQ-6PMF
HistoryApr 23, 2022 - 12:40 a.m.

Unrestricted Upload of File with Dangerous Type in Apache Struts2

2022-04-2300:40:23
Google
osv.dev
5

0.002 Low

EPSS

Percentile

59.8%

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. A patch exists as of version 2.5.22.

References

0.002 Low

EPSS

Percentile

59.8%

Related for OSV:GHSA-8M5Q-CRQQ-6PMF