logo

Database

Lack of data validation In org.apache.struts:struts2-core

Description

Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions