GHSA-876p-4wgc-75rx
Dashboard / Vulnerabilities / GHSA-876p-4wgc-75rx
Summary: Apache Struts RCE Vulnerability
Details: Apache Struts 2.x before 2.3.20.3, 2.3.24.3, and 2.3.28 allows remote attackers to execute arbitrary code via a `%{}` sequence in a tag attribute, aka forced double OGNL evaluation.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-0785, https://github.com/apache/struts/commit/15857a69e7baf3675804495a5954cd0756ac8364, https://github.com/apache/struts, https://web.archive.org/web/20210123095715/http://www.securityfocus.com/bid/85066, https://web.archive.org/web/20220118185853/http://www.securitytracker.com/id/1035271, http://struts.apache.org/docs/s2-029.html
Affected packages
Package
Name: org.apache.struts:struts2-core
Purl: pkg:maven/org.apache.struts/struts2-core
Affected ranges
Type: ECOSYSTEM
Events:
