Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Who should read this

All Struts 2 developers and users

Impact of vulnerability

Possibility to change internal state of session, request, etc

Maximum security rating

MediumModerate

Recommendation

Developers should immediately upgrade to Struts 2.3.20

Affected Software

Struts 2.0.0 - Struts 2.3.16.3

Reporter

Zubair Ashraf of IBM X-Force

CVE Identifier

CVE-2014-0116 - Struts' internals manipulation via CookieInterceptor

...