CVE-2010-1870

EPSS 92.5%

Server side object manipulation in Apache Struts

發布日:2022/5/13修改日:2024/12/2

描述

OGNL provides, among other features, extensive expression evaluation capabilities. This vulnerability allows a malicious user to bypass the '#'-usage protection built into the ParametersInterceptor, thus being able to manipulate server side context objects. This behavior was already addressed in [S2-003](https://cwiki.apache.org/confluence/display/WW/S2-003), but it turned out that the resulting fix based on whitelisting acceptable parameter names closed the vulnerability only partially.

受影響套件(1)

參考連結(10)