Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1tbWo2LWNqajQtaHByNc4AATRH
Apache Struts vulnerable to arbitrary remote code execution due to improper input validation
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an !
(exclamation mark) operator to the REST Plugin.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tbWo2LWNqajQtaHByNc4AATRH
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: almost 2 years ago
Updated: 4 months ago
CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-mmj6-cjj4-hpr5, CVE-2016-3087
References:
- https://nvd.nist.gov/vuln/detail/CVE-2016-3087
- https://www.exploit-db.com/exploits/39919/
- http://struts.apache.org/docs/s2-033.html
- http://www-01.ibm.com/support/docview.wss?uid=swg21987854
- https://github.com/apache/struts/commit/6bd694b7980494c12d49ca1bf39f12aec3e03e2f
- https://web.archive.org/web/20160616082237/http://www.securitytracker.com/id/1036017
- https://web.archive.org/web/20160728170709/http://www.securityfocus.com/bid/90960
- https://github.com/advisories/GHSA-mmj6-cjj4-hpr5
Blast Radius: 37.2
Affected Packages
maven:org.apache.struts:struts2-core
Dependent packages: 194Dependent repositories: 6,183
Downloads:
Affected Version Ranges: >= 2.3.25, < 2.3.28.1, >= 2.3.21, < 2.3.24.3, >= 2.3.19, < 2.3.20.3
Fixed in: 2.3.28.1, 2.3.24.3, 2.3.20.3
All affected versions:
All unaffected versions: 2.0.5, 2.0.6, 2.0.8, 2.0.9, 2.0.11, 2.0.12, 2.0.14, 2.1.2, 2.1.6, 2.1.8, 2.2.1, 2.2.3, 2.3.1, 2.3.3, 2.3.4, 2.3.7, 2.3.8, 2.3.12, 2.3.14, 2.3.15, 2.3.16, 2.3.20, 2.3.24, 2.3.28, 2.3.29, 2.3.30, 2.3.31, 2.3.32, 2.3.33, 2.3.34, 2.3.35, 2.3.36, 2.3.37, 2.5.1, 2.5.2, 2.5.5, 2.5.8, 2.5.10, 2.5.12, 2.5.13, 2.5.14, 2.5.16, 2.5.17, 2.5.18, 2.5.20, 2.5.22, 2.5.25, 2.5.26, 2.5.27, 2.5.28, 2.5.29, 2.5.30, 2.5.31, 2.5.32, 2.5.33, 6.0.0, 6.0.3, 6.1.1, 6.1.2, 6.2.0, 6.3.0, 6.4.0