CVE-2012-0394
Apache Struts's DebuggingInterceptor component allows remote code execution in developer mode
EPSS 74.4%
描述
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
如何修補 CVE-2012-0394
要修補 CVE-2012-0394,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.struts.xwork:xwork-core—升級至 2.3.18 或更新版本
CVE-2012-0394 正在被利用嗎?
可能 — EPSS 為 74.4%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.3.18