Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Special top object can be used to access Struts' internals

GHSA-4qgj-9mvg-3929 · CVE-2015-5209

Published · Modified

Description

ValueStack defines special top object which represents root of execution context. It can be used to manipulate Struts' internals or can be used to affect container's settings. Applying better regex which includes pattern to exclude request parameters trying to use top object. This issue was patched in Struts 2.3.24.1.

Ready to move

Start Securing

Free, no credit card | First findings in minutes