CVE-2010-1870
Server side object manipulation in Apache Struts
EPSS 91.1%
描述
OGNL provides, among other features, extensive expression evaluation capabilities. This vulnerability allows a malicious user to bypass the '#'-usage protection built into the ParametersInterceptor, thus being able to manipulate server side context objects. This behavior was already addressed in [S2-003](https://cwiki.apache.org/confluence/display/WW/S2-003), but it turned out that the resulting fix based on whitelisting acceptable parameter names closed the vulnerability only partially.
如何修補 CVE-2010-1870
要修補 CVE-2010-1870,請將受影響套件升級到下列已修補版本。
- —升級至 2.2.1 或更新版本
CVE-2010-1870 正在被利用嗎?
可能 — EPSS 為 91.1%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.2.1