Lucene search

K
osvGoogleOSV:GHSA-HXQQ-W4MR-MC62
HistoryMay 04, 2022 - 12:29 a.m.

Apache Struts's ParameterInterceptor component does not prevent access to public constructors

2022-05-0400:29:43
Google
osv.dev
7

6.8 Medium

AI Score

Confidence

Low

0.919 High

EPSS

Percentile

98.9%

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

6.8 Medium

AI Score

Confidence

Low

0.919 High

EPSS

Percentile

98.9%