Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Who should read this

All Struts 2 developers and users

Impact of vulnerability

Remote command execution, remote server context manipulation, injection of malicious client side code

Maximum security rating

Highly Critical

Recommendation

Developers should immediately upgrade to Struts 2.3.14.2

Affected Software

Struts 2.0.0 - Struts 2.3.14.1

Reporter

Eric Kobrin and Douglas Rodrigues (Akamai), Coverity Security Research Laboratory, NSFOCUS Security Team

CVE Identifier

CVE-2013-2115, CVE-2013-1966

...