Описание
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libstruts1.2-java | not-affected | package |
Примечания
https://cwiki.apache.org/confluence/display/WW/S2-009
http://blog.o0o.nu/2012/01/cve-2011-3923-yet-another-struts2.html
EPSS
Процентиль: 100%
0.88829
Высокий
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 7 лет назад
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
CVSS3: 9.8
nvd
почти 7 лет назад
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
CVSS3: 9.8
github
больше 4 лет назад
Struts ParameterInterceptor vulnerability allows remote command execution
EPSS
Процентиль: 100%
0.88829
Высокий