Apache Struts vulnerabilities
90 known vulnerabilities affecting apache/struts.
Total CVEs
90
CISA KEV
8
actively exploited
Public exploits
37
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH32MEDIUM35LOW1
Vulnerabilities
Page 2 of 5
CVE-2019-0230P1CRITICALCVSS 9.8PoC≥ 2.0.0, ≤ 2.5.202020-09-14
CVE-2019-0230 [CRITICAL] CWE-1321 CVE-2019-0230: Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
nvd
CVE-2016-3087P1CRITICALCVSS 9.8PoCv2.3.20v2.3.20.1+3 more2016-06-07
CVE-2016-3087 [CRITICAL] CWE-20 CVE-2016-3087: Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invo
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
nvd
CVE-2013-1965P2CRITICALCVSS 9.3PoC≥ 2.0.0, < 2.3.14.12013-07-10
CVE-2013-1965 [CRITICAL] CWE-94 CVE-2013-1965: Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
nvd
CVE-2020-26258P2HIGHCVSS 7.7PoCfixed in 6.0.02020-12-16
CVE-2020-26258 [HIGH] CWE-918 CVE-2020-26258: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. I
nvd
CVE-2013-1966P2CRITICALCVSS 9.3PoC≥ 2.0.0, < 2.3.14.12013-07-10
CVE-2013-1966 [CRITICAL] CWE-94 CVE-2013-1966: Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
nvd
CVE-2013-2115P2HIGHCVSS 8.1PoC≥ 2.0.0, ≤ 2.3.14.12013-07-10
CVE-2013-2115 [HIGH] CVE-2013-2115: Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
nvd
CVE-2012-0392P2MEDIUMCVSS 6.8PoC≥ 2.0.0, < 2.3.12012-01-08
CVE-2012-0392 [MEDIUM] CVE-2012-0392: The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whit
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
nvd
CVE-2012-1592P2HIGHCVSS 8.8PoCv2.0.02019-12-05
CVE-2012-1592 [HIGH] CWE-434 CVE-2012-1592: A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which co
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
nvd
CVE-2012-0394P2MEDIUMCVSS 6.8PoC≥ 2.0.0, ≤ 2.3.172012-01-08
CVE-2012-0394 [MEDIUM] CWE-94 CVE-2012-0394: The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, all
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
nvd
CVE-2010-1870P3MEDIUMCVSS 5.0PoCv2.0.0v2.0.1+24 more2010-08-17
CVE-2010-1870 [MEDIUM] CVE-2010-1870: The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as use
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAc
nvd
CVE-2012-0393P2MEDIUMCVSS 6.4PoC≥ 2.1.0, < 2.3.1.12012-01-08
CVE-2012-0393 [MEDIUM] CWE-264 CVE-2012-0393: The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
nvd
CVE-2013-2248P3MEDIUMCVSS 5.8PoCv2.0.0v2.0.1+42 more2013-07-20
CVE-2013-2248 [MEDIUM] CWE-20 CVE-2013-2248: Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
nvd
CVE-2008-6505P3MEDIUMCVSS 5.0PoCv2.0.6v2.0.8+5 more2009-03-23
CVE-2008-6505 [MEDIUM] CWE-22 CVE-2008-6505: Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.
nvd
CVE-2008-6504P3MEDIUMCVSS 5.0PoCv2.0.0v2.0.2+10 more2009-03-23
CVE-2008-6504 [MEDIUM] CWE-20 CVE-2008-6504: ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Ap
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated b
nvd
CVE-2020-26259P3MEDIUMCVSS 6.8fixed in 6.0.02020-12-16
CVE-2020-26259 [MEDIUM] CWE-78 CVE-2020-26259: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as log as the executing process has sufficient rights only by manipulating th
nvd
CVE-2016-3082P2CRITICALCVSS 9.8v2.0.0v2.0.1+54 more2016-04-26
CVE-2016-3082 [CRITICAL] CWE-20 CVE-2016-3082: XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.2
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
nvd
CVE-2016-4438P2CRITICALCVSS 9.8v2.3.20v2.3.20.1+5 more2016-07-04
CVE-2016-4438 [CRITICAL] CWE-20 CVE-2016-4438: The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitr
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
nvd
CVE-2016-6795P2CRITICALCVSS 9.8v2.3.20v2.3.20.1+16 more2017-09-20
CVE-2016-6795 [CRITICAL] CWE-22 CVE-2016-6795: In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possibl
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
nvd
CVE-2011-5057P3MEDIUMCVSS 5.0PoC≥ 2.0.0, < 2.3.32012-01-08
CVE-2011-5057 [MEDIUM] CWE-264 CVE-2011-5057: Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, Req
nvd
CVE-2019-0233P3HIGHCVSS 7.5≥ 2.0.0, ≤ 2.5.202020-09-14
CVE-2019-0233 [HIGH] CWE-281 CVE-2019-0233: An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when pe
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
nvd