Lucene search

K
osvGoogleOSV:GHSA-9CCM-G362-2R35
HistoryMay 14, 2022 - 2:55 a.m.

XWork in Apache Struts Reveals Sensitive Information

2022-05-1402:55:17
Google
osv.dev
8

0.004 Low

EPSS

Percentile

75.1%

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.