Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28516
HistoryDec 09, 2020 - 5:42 a.m.

Remote Code Execution

2020-12-0905:42:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.973 High

EPSS

Percentile

99.9%

struts2-core is vulnerable to remote code execution. Tag attributes can be used to perform a double evaluation when forced OGNL evaluation is applied, by using the %{...} syntax. This can lead to remote code execution when an attacker provides a malicious input to be evaluated.

CPENameOperatorVersion
struts 2 corele2.5.25
struts 2 corele2.5.25