QID 995344
Date Published: 2023-09-22
QID 995344: Java (Maven) Security Update for org.apache.struts:struts2-parent (GHSA-4wrr-9h5r-m92w)
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4wrr-9h5r-m92w for updates and patch information.
Vendor References
- GHSA-4wrr-9h5r-m92w -
github.com/advisories/GHSA-4wrr-9h5r-m92w
CVEs related to QID 995344
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4wrr-9h5r-m92w | org.apache.struts:struts2-parent |
|