Prototype Pollution In org.apache.struts:struts2-core
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Apache Struts Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.5.22 | ||
rpm rhel5 | - | - |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.