Apache Struts 'CookieInterceptor' Security Bypass Vulnerability
BID:67218
Info
Apache Struts 'CookieInterceptor' Security Bypass Vulnerability
| Bugtraq ID: | 67218 |
| Class: | Design Error |
| CVE: |
CVE-2014-0116 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2014 12:00AM |
| Updated: | Apr 16 2015 06:14PM |
| Credit: | Zubair Ashraf of IBM X-Force |
| Vulnerable: |
Apache Software Foundation Struts 2.2.3 Apache Software Foundation Struts 2.2.1 1 Apache Software Foundation Struts 2.2 Apache Software Foundation Struts 2.1.8 .1 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.6 Apache Software Foundation Struts 2.1.5 Apache Software Foundation Struts 2.1.2 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1.1 Apache Software Foundation Struts 2.1 Apache Software Foundation Struts 2.0.14 Apache Software Foundation Struts 2.0.12 Apache Software Foundation Struts 2.0.11 .2 Apache Software Foundation Struts 2.0.11 .1 Apache Software Foundation Struts 2.0.11 Apache Software Foundation Struts 2.0.10 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 Apache Software Foundation Struts 2.3.1.2 Apache Software Foundation Struts 2.3.1.1 Apache Software Foundation Struts 2.2.3.1 Apache Software Foundation Struts 2.1.8 Apache Software Foundation Struts 2.1.4 Apache Software Foundation Struts 2.1.3 Apache Software Foundation Struts 2.0.13 |
| Not Vulnerable: | |
Discussion
Apache Struts 'CookieInterceptor' Security Bypass Vulnerability
Apache Struts is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Apache Struts versions 2.0.0 through 2.3.16.2 are vulnerable.
Apache Struts is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
Apache Struts versions 2.0.0 through 2.3.16.2 are vulnerable.
Exploit / POC
Apache Struts 'CookieInterceptor' Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Apache Struts 'CookieInterceptor' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Struts 'CookieInterceptor' Security Bypass Vulnerability
References:
References:
- Struts Homepage (Apache Software Foundation)