Lucene search

K
osvGoogleOSV:GHSA-MMJ6-CJJ4-HPR5
HistoryMay 14, 2022 - 12:54 a.m.

Apache Struts vulnerable to arbitrary remote code execution due to improper input validation

2022-05-1400:54:14
Google
osv.dev
9

7.7 High

AI Score

Confidence

Low

0.465 Medium

EPSS

Percentile

97.5%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

7.7 High

AI Score

Confidence

Low

0.465 Medium

EPSS

Percentile

97.5%