CVE-2013-4310
published 2013-09-30CVE-2013-4310: Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
PriorityP345medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
7.46%
93.8th percentile
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Struts2 Broken Access Control Vulnerability
ghsa·2022-05-17
CVE-2013-4310 [MEDIUM] CWE-284 Apache Struts2 Broken Access Control Vulnerability
Apache Struts2 Broken Access Control Vulnerability
The Struts 2 action mapping mechanism supports the special parameter prefix action: which is intended to help with attaching navigational information to buttons within forms, under certain conditions this can be used to bypass security constraints.
In Struts 2.3.15.3 the action mapping mechanism was changed to avoid circumventing security constraints. Two additional constants were introduced to steer behaviour of DefaultActionMapper:
- struts.mapper.action.prefix.enabled - when set to false support for "action:" prefix is disabled, set to false by default
- struts.mapper.action.prefix.crossNamespaces - when set to false, actions defined with "action:" prefix must be in the same namespace as current action
OSV
Apache Struts2 Broken Access Control Vulnerability
osv·2022-05-17
CVE-2013-4310 [MEDIUM] Apache Struts2 Broken Access Control Vulnerability
Apache Struts2 Broken Access Control Vulnerability
The Struts 2 action mapping mechanism supports the special parameter prefix action: which is intended to help with attaching navigational information to buttons within forms, under certain conditions this can be used to bypass security constraints.
In Struts 2.3.15.3 the action mapping mechanism was changed to avoid circumventing security constraints. Two additional constants were introduced to steer behaviour of DefaultActionMapper:
- struts.mapper.action.prefix.enabled - when set to false support for "action:" prefix is disabled, set to false by default
- struts.mapper.action.prefix.crossNamespaces - when set to false, actions defined with "action:" prefix must be in the same namespace as current action
Red Hat
struts: broken access control vulnerability
vendor_redhat·2013-09-21·CVSS 5.8
CVE-2013-4310 [MEDIUM] struts: broken access control vulnerability
struts: broken access control vulnerability
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
Package: struts (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.htmlhttp://archives.neohapsis.com/archives/bugtraq/2013-10/0083.htmlhttp://secunia.com/advisories/54919http://secunia.com/advisories/56483http://secunia.com/advisories/56492http://struts.apache.org/release/2.3.x/docs/s2-018.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securitytracker.com/id/1029077http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.htmlhttp://archives.neohapsis.com/archives/bugtraq/2013-10/0083.htmlhttp://secunia.com/advisories/54919http://secunia.com/advisories/56483http://secunia.com/advisories/56492http://struts.apache.org/release/2.3.x/docs/s2-018.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securitytracker.com/id/1029077
2013-09-30
Published