CVE-2025-54656
Description
UNSUPPORTED WHEN ASSIGNED Improper Output Neutralization for Logs vulnerability in Apache Struts.
This issue affects Apache Struts Extras: before 2.
When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without any filtering. Specially-crafted input may lead to log output where part of the message masquerades as a separate log line, confusing consumers of the logs (either human or automated).
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.struts:struts-extrasMaven | <= 1.3.10 | — |
Affected products
4cpe:2.3:a:apache:struts_extras:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:struts_extras:*:*:*:*:*:*:*:*range: <2.0
- (no CPE)range: 0
- ghsa-coords2 versions
<= 1.3.10+ 1 more
- (no CPE)range: <= 1.3.10
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-cx25-xg7c-xfm5ghsaADVISORY
- lists.apache.org/thread/so5cn07j2zn9vlf1xnfqp630wts719rrnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-54656ghsaADVISORY
- www.openwall.com/lists/oss-security/2025/07/30/1nvdWEB
News mentions
0No linked articles in our index yet.