Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Excerpt

Getter as action method leads to security bypass


Who should read this

All Struts 2 developers and users

Impact of vulnerability

Possible manipulation of return result and bypassing validation

Maximum security rating

Medium

Moderate

Recommendation

Upgrade to Struts 2.3.29.

Affected Software

Struts 2.3.20 - Struts Struts 2.3.28.1

Reporter

Takeshi Terada websec02 dot g02 at gmail.com

CVE Identifier

CVE-2016-4433

Problem

It is possible to pass a crafted request which can be used to bypass internal security mechanism and manipulate return string which can leads to redirecting user to unvalidated location.

...

Some backward incompatibility issues are expected when upgrading to Struts 2.3.28 29 - it can happen that some OGNL expressions stop working because of performing disallowed arithmetic operations and assignments.

...