Security controls bypass or absence In org.apache.struts:struts2-core
Description
Incomplete exclude pattern in Apache Struts The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors. In Struts 2.3.20.1 a better set of exlude patterns was defined.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.3.20.1 | ||
maven | 2.3.20.1 |
Aliases
1. 2. 3. 4.
References
1. 2.