Apache Struts's ParameterInterceptor component does not prevent access to public constructors
Moderate severity
GitHub Reviewed
Published
May 4, 2022
to the GitHub Advisory Database
•
Updated Mar 14, 2024
Description
Published by the National Vulnerability Database
Jan 8, 2012
Published to the GitHub Advisory Database
May 4, 2022
Reviewed
Dec 27, 2023
Last updated
Mar 14, 2024
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
References