-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The CVE and advisories explicitly link the vulnerability to FilterDispatcher (2.0.x) and DefaultStaticContentLoader (2.1.x). The commit diff for DefaultStaticContentLoader shows the findStaticResource method was modified to add path validation, confirming its role. For FilterDispatcher, the Struts S2-004 documentation and CVE description identify it as the vulnerable component in 2.0.x, with the serveStaticResource method being the logical point of failure for static content handling. Both functions lacked proper path normalization/validation, enabling directory traversal.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.struts:struts2-core | maven | >= 2.0.0, < 2.0.12 | 2.0.12 |
| org.apache.struts:struts2-core | maven | >= 2.1.0, < 2.1.3 | 2.1.3 |
Ongoing coverage of React2Shell