Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c6q-rgvj-66rx

Опубликовано: 02 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache Tiles Vulnerable to XSS via EL Expression Injection

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.

Пакеты

Наименование

org.apache.tiles:tiles-core

maven
Затронутые версииВерсия исправления

>= 2.1, < 2.1.2

2.1.2

EPSS

Процентиль: 78%
0.01152
Низкий

Дефекты

CWE-87
CWE-917

Связанные уязвимости

nvd
больше 16 лет назад

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.

debian
больше 16 лет назад

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other prod ...

EPSS

Процентиль: 78%
0.01152
Низкий

Дефекты

CWE-87
CWE-917