QID 995344

Date Published: 2023-09-22

QID 995344: Java (Maven) Security Update for org.apache.struts:struts2-parent (GHSA-4wrr-9h5r-m92w)

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Github security advisory GHSA-4wrr-9h5r-m92w for updates and patch information.
    Vendor References

    CVEs related to QID 995344

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4wrr-9h5r-m92w org.apache.struts:struts2-parent URL Logo github.com/advisories/GHSA-4wrr-9h5r-m92w