CVE-2015-5209
Special top object can be used to access Struts' internals
7.5
HIGH
CVSS 3.1
EPSS 9.1%
描述
ValueStack defines special top object which represents root of execution context. It can be used to manipulate Struts' internals or can be used to affect container's settings. Applying better regex which includes pattern to exclude request parameters trying to use top object. This issue was patched in Struts 2.3.24.1.
如何修補 CVE-2015-5209
要修補 CVE-2015-5209,請將受影響套件升級到下列已修補版本。
- —升級至 2.3.24.1 或更新版本
CVE-2015-5209 正在被利用嗎?
中等 — EPSS 為 9.1%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.3.24.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |