Enhancement: cves/2019/CVE-2019-0230.yaml by mp

patch-1
MostInterestingBotInTheWorld 2022-05-16 15:27:10 -04:00
parent 874996c177
commit 61aac95bb6
1 changed files with 1 additions and 1 deletions

View File

@ -4,7 +4,7 @@ info:
name: Apache Struts <=2.5.20 - Remote Code Execution
author: geeknik
severity: critical
description: Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
description: Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation when evaluated on raw user input in tag attributes, which may lead to remote code execution.
reference:
- https://cwiki.apache.org/confluence/display/WW/S2-059
- https://www.tenable.com/blog/cve-2019-0230-apache-struts-potential-remote-code-execution-vulnerability