QID 981081
QID 981081: Java (maven) Security Update for org.apache.struts:struts2-rest-plugin (GHSA-gg9m-fj3v-r58c)
The REST Plugin in Apache Struts 2.1.2 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gg9m-fj3v-r58c for updates pertaining to this vulnerability.
Vendor References
- GHSA-gg9m-fj3v-r58c -
github.com/advisories/GHSA-gg9m-fj3v-r58c
CVEs related to QID 981081
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gg9m-fj3v-r58c | org.apache.struts:struts2-rest-plugin |
|