CVE-2015-2992
published 2020-02-27CVE-2015-2992: Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
5.76%
92.2th percentile
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | >= 2.0.0 < 2.3.20 | 2.3.20 |
| apache_software_foundation | apache_struts | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site Scripting in Apache Struts
osv·2022-05-24
CVE-2015-2992 [MEDIUM] Cross-site Scripting in Apache Struts
Cross-site Scripting in Apache Struts
When the Struts2 debug mode is turned on, under certain conditions an arbitrary script may be executed in the 'Problem Report' screen. Also if JSP files are exposed to be accessed directly it's possible to execute an arbitrary script.
It is generally not advisable to have debug mode switched on outside of the development environment. Debug mode should always be turned off in production setup. Also never expose JSPs files directly and hide them inside WEB-INF folder or define dedicated security constraints to block access to raw JSP files.
Struts >= 2.3.20 is not vulnerable to this attack. We recommend upgrading to Struts 2.3.20 or higher if turning off debug mode is not possible.
GHSA
Cross-site Scripting in Apache Struts
ghsa·2022-05-24
CVE-2015-2992 [MEDIUM] CWE-79 Cross-site Scripting in Apache Struts
Cross-site Scripting in Apache Struts
When the Struts2 debug mode is turned on, under certain conditions an arbitrary script may be executed in the 'Problem Report' screen. Also if JSP files are exposed to be accessed directly it's possible to execute an arbitrary script.
It is generally not advisable to have debug mode switched on outside of the development environment. Debug mode should always be turned off in production setup. Also never expose JSPs files directly and hide them inside WEB-INF folder or define dedicated security constraints to block access to raw JSP files.
Struts >= 2.3.20 is not vulnerable to this attack. We recommend upgrading to Struts 2.3.20 or higher if turning off debug mode is not possible.
Red Hat
struts: XSS vulnerability when JSP files are exposed to be accessed directly
vendor_redhat·2015-08-26·CVSS 6.1
CVE-2015-2992 [MEDIUM] CWE-79 struts: XSS vulnerability when JSP files are exposed to be accessed directly
struts: XSS vulnerability when JSP files are exposed to be accessed directly
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from our source code could be at risk. Red Hat will remove these artefacts from source co
No detection rules found.
Bugzilla
CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly [epel-7]
bugzilla·2015-09-04·CVSS 6.1
CVE-2015-2992 [MEDIUM] CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly [epel-7]
CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for strut
Bugzilla
CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly
bugzilla·2015-09-04·CVSS 6.1
CVE-2015-2992 [MEDIUM] CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly
CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly
Arbitrary script can be executed when JSP files are exposed to be accessed directly. Affected versions are Struts 2.0.0 - 2.3.16.3.
External reference:
https://struts.apache.org/docs/s2-025.html
Discussion:
Created struts tracking bugs for this issue:
Affects: fedora-all [bug 1260104]
Affects: epel-7 [bug 1260105]
---
Affected Software: Struts 2.0.0 - Struts Struts 2.3.16.3
---
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause
http://jvn.jp/en/jp/JVN88408929/index.htmlhttp://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000124.htmlhttp://www.securityfocus.com/bid/76624https://security.netapp.com/advisory/ntap-20200330-0001/http://jvn.jp/en/jp/JVN88408929/index.htmlhttp://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000124.htmlhttp://www.securityfocus.com/bid/76624https://security.netapp.com/advisory/ntap-20200330-0001/
2020-02-27
Published