-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.struts:struts2-core | maven | < 2.2.3.1 | 2.2.3.1 |
| org.apache.struts.xwork:xwork-core | maven | < 2.2.3.1 | 2.2.3.1 |
The vulnerability stems from improper handling of user input during conversion errors. Key vulnerable functions were identified by: