Critical severity9.8NVD Advisory· Published Nov 1, 2019· Updated Jun 16, 2026
CVE-2011-3923
CVE-2011-3923
Description
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.struts:struts2-coreMaven | >= 2.0.0, < 2.3.1.2 | 2.3.1.2 |
Affected products
4- cpe:2.3:a:redhat:jboss_enterprise_web_server:1.0.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-j68f-8h6p-9h5qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-3923ghsaADVISORY
- blog.o0o.nu/2012/01/cve-2011-3923-yet-another-struts2.htmlghsaWEB
- struts.apache.org/development/2.x/docs/s2-009.htmlghsaWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/72585nvdWEB
- security-tracker.debian.org/tracker/CVE-2011-3923nvdWEB
- web.archive.org/web/20140725074137/http://seclists.org/fulldisclosure/2014/Jul/38ghsaWEB
- seclists.org/fulldisclosure/2014/Jul/38nvd
- www.exploit-db.com/exploits/24874nvd
- www.securityfocus.com/bid/51628nvd
- www.securitytracker.com/idnvd
News mentions
0No linked articles in our index yet.