[MAVEN:GHSA-2PPP-XJ34-VVF7] Apache Struts's CookieInterceptor component does not use the parameter-name whitelist

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

ID
MAVEN:GHSA-2PPP-XJ34-VVF7
Severity
moderate
URL
https://github.com/advisories/GHSA-2ppp-xj34-vvf7
Published
2022-05-04T00:29:43
(2 years ago)
Modified
2023-12-27T20:13:28
(8 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.struts/struts2-core org.apache.struts struts2-core < 2.2.3.1
Fixed pkg:maven/org.apache.struts/struts2-core org.apache.struts struts2-core = 2.2.3.1
Affected pkg:maven/org.apache.struts.xwork/xwork-core org.apache.struts.xwork xwork-core < 2.2.3.1
Fixed pkg:maven/org.apache.struts.xwork/xwork-core org.apache.struts.xwork xwork-core = 2.2.3.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...