VYPR

Maven package

org.apache.struts/struts-tiles

pkg:maven/org.apache.struts/struts-tiles

Vulnerabilities (1)

  • CVE-2023-49735Nov 30, 2023
    affected >= 1.3.0, <= 1.3.10

    ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passin