Lack of data validation In org.apache.struts:struts2-core
Description
Apache Struts improper action name cleanup Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.3.29, 2.5.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7.