Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2017-9805

около 9 лет назад

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS3: 8.1
EPSS: Критический
redhat логотип

CVE-2017-9805

около 9 лет назад

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS3: 8.1
EPSS: Критический
nvd логотип

CVE-2017-9805

около 9 лет назад

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS3: 8.1
EPSS: Критический
debian логотип

CVE-2017-9805

около 9 лет назад

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and ...

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-gg9m-fj3v-r58c

почти 8 лет назад

REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering

CVSS3: 8.1
EPSS: Критический
fstec логотип

BDU:2017-02058

около 9 лет назад

Уязвимость плагина REST программной платформы Apache Struts, позволяющая нарушителю выполнить произвольный код

CVSS2: 7.6
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS3: 8.1
99%
Критический
около 9 лет назад
redhat логотип
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS3: 8.1
99%
Критический
около 9 лет назад
nvd логотип
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS3: 8.1
99%
Критический
около 9 лет назад
debian логотип
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and ...

CVSS3: 8.1
99%
Критический
около 9 лет назад
github логотип
GHSA-gg9m-fj3v-r58c

REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering

CVSS3: 8.1
99%
Критический
почти 8 лет назад
fstec логотип
BDU:2017-02058

Уязвимость плагина REST программной платформы Apache Struts, позволяющая нарушителю выполнить произвольный код

CVSS2: 7.6
99%
Критический
около 9 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.