Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache struts 2.3.20.3 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2016-4438
The REST plugin in Apache Struts 2 2.3.19 up to and including 2.3.28.1 allows remote malicious users to execute arbitrary code via a crafted expression.
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
5
CVSSv2
CVE-2016-4431
Apache Struts 2 2.3.20 up to and including 2.3.28.1 allows remote malicious users to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
5
CVSSv2
CVE-2016-4433
Apache Struts 2 2.3.20 up to and including 2.3.28.1 allows remote malicious users to bypass intended access restrictions and conduct redirection attacks via a crafted request.
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
6.8
CVSSv2
CVE-2016-4430
Apache Struts 2 2.3.20 up to and including 2.3.28.1 mishandles token validation, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
5
CVSSv2
CVE-2016-4465
The URLValidator class in Apache Struts 2 2.3.20 up to and including 2.3.28.1 and 2.5.x prior to 2.5.1 allows remote malicious users to cause a denial of service via a null value for a URL field.
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.5
7.5
CVSSv2
CVE-2016-6795
In the Convention plugin in Apache Struts 2.3.x prior to 2.3.31, and 2.5.x prior to 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.2
Apache Struts 2.3.20.3
Apache Struts 2.3.21
Apache Struts 2.3.22
Apache Struts 2.3.23
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
Apache Struts 2.3.25
7.5
CVSSv2
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
2 EDB exploits
7 Github repositories
1 Article
5
CVSSv2
CVE-2016-3093
Apache Struts 2.0.0 up to and including 2.3.24.1 does not properly cache method references when used with OGNL prior to 3.0.12, which allows remote malicious users to cause a denial of service (block access to a web site) via unspecified vectors.
Ognl Project Ognl
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.10
5
CVSSv2
CVE-2017-9787
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.10
Apache Struts 2.3.11
Apache Struts 2.3.12
Apache Struts 2.3.13
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
1 Article
7.5
CVSSv2
CVE-2016-4436
Apache Struts 2 prior to 2.3.29 and 2.5.x prior to 2.5.1 allow malicious users to have unspecified impact via vectors related to improper action name clean up.
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.11
Apache Struts 2.0.11.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-12326
CVE-2024-44852
XSS
privilege escalation
CSRF
CVE-2024-12115
CVE-2024-38925
CVE-2024-38144
CVE-2024-6387
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »