Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Improper Control of Generation of Code in Apache Struts

GHSA-whmq-v94q-34p9 · CVE-2013-1965

Published · Modified

Description

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

Ready to move

Start Securing

Free, no credit card | First findings in minutes