[MAVEN:GHSA-WM8W-QP2F-728Q] Apache Struts Open Redirect

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

Package Affected Version
pkg:maven/org.apache.struts.xwork/xwork-core >= 2.3.20, <= 2.3.28.1
Package Fixed Version
pkg:maven/org.apache.struts.xwork/xwork-core = 2.3.29
ID
MAVEN:GHSA-WM8W-QP2F-728Q
Severity
high
URL
https://github.com/advisories/GHSA-wm8w-qp2f-728q
Published
2022-05-17T02:16:00
(2 years ago)
Modified
2024-01-04T18:29:30
(8 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.struts.xwork/xwork-core org.apache.struts.xwork xwork-core >= 2.3.20 <= 2.3.28.1
Fixed pkg:maven/org.apache.struts.xwork/xwork-core org.apache.struts.xwork xwork-core = 2.3.29
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...