Server side template injection In org.apache.struts:struts2-rest-plugin
Description
Code injection in Apache Struts Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.3.15.2 | ||
maven | 2.3.15.2 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.