[MAVEN:GHSA-HMVJ-GC9Q-MG9P] Apache Struts's DebuggingInterceptor component allows remote code execution in developer mode

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."

Package Affected Version
pkg:maven/org.apache.struts.xwork/xwork-core < 2.3.18
Package Fixed Version
pkg:maven/org.apache.struts.xwork/xwork-core = 2.3.18
ID
MAVEN:GHSA-HMVJ-GC9Q-MG9P
Severity
moderate
URL
https://github.com/advisories/GHSA-hmvj-gc9q-mg9p
Published
2022-05-04T00:29:43
(2 years ago)
Modified
2023-12-27T20:24:32
(8 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.struts.xwork/xwork-core org.apache.struts.xwork xwork-core < 2.3.18
Fixed pkg:maven/org.apache.struts.xwork/xwork-core org.apache.struts.xwork xwork-core = 2.3.18
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...