VYPR

Struts

by Apache

Source repositories

CVEs (95)

  • CVE-2016-4433HigJul 4, 2016
    risk 0.43cvss 7.5epss 0.09

    Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

  • CVE-2016-4431HigJul 4, 2016
    risk 0.43cvss 7.5epss 0.09

    Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

  • CVE-2023-41835HigDec 5, 2023
    risk 0.42cvss 7.5epss 0.07

    When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts…

  • CVE-2018-1327HigMar 27, 2018
    risk 0.42cvss 7.5epss 0.08

    The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described…

  • CVE-2017-9804HigSep 20, 2017
    risk 0.42cvss 7.5epss 0.08

    In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. …

  • CVE-2020-26258MedDec 16, 2020
    risk 0.41cvss 6.3epss 0.82

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are…

  • CVE-2017-15707MedDec 1, 2017
    risk 0.41cvss 6.2epss 0.10

    In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

  • CVE-2015-2992MedFeb 27, 2020
    risk 0.40cvss 6.1epss 0.06

    Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

  • CVE-2015-5169MedSep 25, 2017
    risk 0.40cvss 6.1epss 0.07

    Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

  • CVE-2017-7672MedJul 13, 2017
    risk 0.39cvss 5.9epss 0.09

    If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.

  • CVE-2016-3093MedJun 7, 2016
    risk 0.35cvss 5.3epss 0.08

    Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

  • CVE-2016-4003MedApr 12, 2016
    risk 0.33cvss 6.1epss 0.10

    Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded…

  • CVE-2016-2162MedApr 12, 2016
    risk 0.33cvss 6.1epss 0.06

    Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.

  • CVE-2016-8738MedSep 20, 2017
    risk 0.32cvss 5.9epss 0.03

    In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

  • CVE-2026-73632MedAug 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD /…

  • CVE-2026-73631MedAug 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be…

  • CVE-2016-4465MedJul 4, 2016
    risk 0.28cvss 5.3epss 0.09

    The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.

  • CVE-2023-34396MedJun 14, 2023
    risk 0.21cvss 4.3epss 0.06

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater

  • CVE-2023-34149MedJun 14, 2023
    risk 0.21cvss 4.3epss 0.05

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.

  • CVE-2014-0112Apr 29, 2014
    risk 0.11cvss —epss 0.98

    ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete…