RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
BID:66041
Info
RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
| Bugtraq ID: | 66041 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2014 12:00AM |
| Updated: | Mar 11 2014 01:02AM |
| Credit: | Mark Thomas (markt at apache.org) and Przemyslaw Celej (p-celej at o2.pl) |
| Vulnerable: |
Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2.1 1 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 .1 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 .2 Apache Software Foundation Struts 2.0.11 .1 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.3.1.2 Apache Software Foundation Struts 2.3.1.1 Apache Software Foundation Struts 2.2.3.1 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: | |
Discussion
RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
Apache Struts is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass security restrictions and perform unauthorized actions.
Apache Struts 2.0.0 through 2.3.16 are vulnerable.
Note: This BID is being retired as a duplicate of the issue discussed in BID 65999 (Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability).
Apache Struts is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass security restrictions and perform unauthorized actions.
Apache Struts 2.0.0 through 2.3.16 are vulnerable.
Note: This BID is being retired as a duplicate of the issue discussed in BID 65999 (Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability).
Exploit / POC
RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RETIRED: Apache Struts CVE-2014-0094 Classloader Manipulation Security Bypass Vulnerability
References:
References:
- Struts Homepage (Apache Software Foundation)