Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

Apache Struts vulnerable to arbitrary remote code execution due to improper input validation

GHSA-mmj6-cjj4-hpr5 · CVE-2016-3087

Published · Modified

Description

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

Ready to move

Start Securing

Free, no credit card | First findings in minutes