logo

Database

Prototype Pollution In org.apache.struts:struts2-core

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Apache Struts Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions