CVE-2017-9805

HIGH8.1⚠ KEVEPSS 94.3%

REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering

發布日:2018/10/16修改日:2025/10/22加入 CISA KEV 日:2021/11/3

描述

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H

參考連結(19)