Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5q8-jghf-3pm3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache Struts2 Broken Access Control Vulnerability

The Struts 2 action mapping mechanism supports the special parameter prefix action: which is intended to help with attaching navigational information to buttons within forms, under certain conditions this can be used to bypass security constraints.

In Struts 2.3.15.3 the action mapping mechanism was changed to avoid circumventing security constraints. Two additional constants were introduced to steer behaviour of DefaultActionMapper:

  • struts.mapper.action.prefix.enabled - when set to false support for "action:" prefix is disabled, set to false by default
  • struts.mapper.action.prefix.crossNamespaces - when set to false, actions defined with "action:" prefix must be in the same namespace as current action

Пакеты

Наименование

org.apache.struts:struts2-core

maven
Затронутые версииВерсия исправления

< 2.3.15.3

2.3.15.3

EPSS

Процентиль: 94%
0.07457
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
почти 13 лет назад

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

redhat
почти 13 лет назад

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

nvd
почти 13 лет назад

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

debian
почти 13 лет назад

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass ...

CVSS3: 7.2
fstec
почти 13 лет назад

Уязвимость реализации механизма сопоставления действий DefaultActionMapper программной платформы Apache Struts, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 94%
0.07457
Низкий

Дефекты

CWE-284