Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4553
HistoryJul 07, 2017 - 9:38 p.m.

Remote Code Execution (RCE)

2017-07-0721:38:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24

0.974 High

EPSS

Percentile

100.0%

struts2-struts1-plugin is vulnerable to remote code execution (RCE) attacks. These attacks are possible because the user input are not sanitized and are directly passed through messages.add() to be used as a part of an error message in the ActionMessage class. This doesn’t affect users of the Struts 2.5.x series or applications that do not use the Struts 1 plugin.

CPENameOperatorVersion
struts 2 showcase webapple2.3.32