CVE-2013-4316
published 2013-09-30CVE-2013-4316: Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
PriorityP341critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.33%
94.3th percentile
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Code injection in Apache Struts
osv·2022-05-17
CVE-2013-4316 [HIGH] Code injection in Apache Struts
Code injection in Apache Struts
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
GHSA
Code injection in Apache Struts
ghsa·2022-05-17
CVE-2013-4316 [HIGH] CWE-94 Code injection in Apache Struts
Code injection in Apache Struts
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Red Hat
struts: dynamic method executions is enabled by default
vendor_redhat·2013-09-21·CVSS 10.0
CVE-2013-4316 [CRITICAL] struts: dynamic method executions is enabled by default
struts: dynamic method executions is enabled by default
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Package: struts (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.htmlhttp://struts.apache.org/release/2.3.x/docs/s2-019.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securitytracker.com/id/1029078http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.htmlhttp://struts.apache.org/release/2.3.x/docs/s2-019.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securitytracker.com/id/1029078
2013-09-30
Published