-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.struts:struts2-core | maven | >= 2.0.0, < 2.5.22 | 2.5.22 |
The vulnerability stems from Struts' failure to exclude java.io/nio packages in property evaluation. The ParametersInterceptor handles parameter binding using OGNL, and the OgnlUtil class performs the actual property operations. The patch modifies excluded packages in struts-default.xml (org/apache/struts2/default.properties) which affects these components' security checks. These functions would appear in stack traces when processing malicious file upload parameters that access File object properties.
Ongoing coverage of React2Shell