QID 981201
QID 981201: Java (maven) Security Update for org.apache.struts:struts2-core (GHSA-8fx9-5hx8-crhm)
In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8fx9-5hx8-crhm for updates pertaining to this vulnerability.
Vendor References
- GHSA-8fx9-5hx8-crhm -
github.com/advisories/GHSA-8fx9-5hx8-crhm
CVEs related to QID 981201
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8fx9-5hx8-crhm | org.apache.struts:struts2-core |
|