Executive brief
Apache Struts's CookieInterceptor component does not use the parameter-name whitelist
Affected products
- Maven org.apache.struts.xwork:xwork-core
- Maven org.apache.struts:struts2-core
Junglewise Threat Intelligence
CVE-2012-0392 · Severity: info · Published 2022-05-04
Technologies: org.apache.struts.xwork:xwork-core (Maven), org.apache.struts:struts2-core (Maven). Vendors: Maven.
Apache Struts's CookieInterceptor component does not use the parameter-name whitelist