UNKNOWN Maven
Server side object manipulation in Apache Struts
GHSA-x5fc-pgpx-59j5 · CVE-2010-1870
Published · Modified
Description
OGNL provides, among other features, extensive expression evaluation capabilities. This vulnerability allows a malicious user to bypass the '#'-usage protection built into the ParametersInterceptor, thus being able to manipulate server side context objects. This behavior was already addressed in S2-003, but it turned out that the resulting fix based on whitelisting acceptable parameter names closed the vulnerability only partially.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2010-1870
- WEB https://cwiki.apache.org/confluence/display/WW/S2-003
- PACKAGE https://github.com/apache/struts
- WEB http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html
- WEB http://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-06-16
- WEB http://packetstormsecurity.com/files/159643/LISTSERV-Maestro-9.0-8-Remote-Code-Execution.html
- WEB http://seclists.org/fulldisclosure/2010/Jul/183
- WEB http://seclists.org/fulldisclosure/2020/Oct/23
- WEB http://struts.apache.org/2.2.1/docs/s2-005.html
- WEB http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140709-struts2
Ready to move
Start Securing
Free, no credit card | First findings in minutes