logo

Database

Lack of data validation In org.apache.struts:struts2-core

Description

Arbitrary code execution in Apache Struts 2 The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions