QID 996912
Date Published: 2024-02-05
QID 996912: Java (Maven) Security Update for org.apache.struts:struts2-core (GHSA-mmj6-cjj4-hpr5)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mmj6-cjj4-hpr5 for updates and patch information.
Vendor References
- GHSA-mmj6-cjj4-hpr5 -
github.com/advisories/GHSA-mmj6-cjj4-hpr5
CVEs related to QID 996912
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mmj6-cjj4-hpr5 | org.apache.struts:struts2-core |
|