Critical severity9.8NVD Advisory· Published Sep 20, 2017· Updated Jun 17, 2026
CVE-2016-6795
CVE-2016-6795
Description
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.struts:struts2-convention-pluginMaven | >= 2.3.0, < 2.3.31 | 2.3.31 |
org.apache.struts:struts2-convention-pluginMaven | >= 2.5.0, < 2.5.5 | 2.5.5 |
Affected products
20cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:apache:struts:2.3.20:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.20.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.20.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.21:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.22:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.23:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.24.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.25:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.26:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.27:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.28:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.28.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.29:*:*:*:*:*:*:*
- cpe:2.3:a:apache:struts:2.3.30:*:*:*:*:*:*:*
- (no CPE)range: 2.3.x before 2.3.31
Patches
Vulnerability mechanics
References
9- www.securityfocus.com/bid/93773nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-44hv-jjx7-qfjgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-6795ghsaADVISORY
- struts.apache.org/docs/s2-042.htmlnvdVendor AdvisoryWEB
- github.com/apache/struts/commit/8e67b9144aa643769b261e2492cb561e04d016abghsaWEB
- github.com/apache/struts/commit/c1869f4989942dd33fa4e189e0ac1f766fb5ac14ghsaWEB
- security.netapp.com/advisory/ntap-20180629-0003ghsaWEB
- web.archive.org/web/20200227214705/http://www.securityfocus.com/bid/93773ghsaWEB
- security.netapp.com/advisory/ntap-20180629-0003/nvd
News mentions
0No linked articles in our index yet.