Executive brief
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x allows remote code execution via improper input validation. An attacker can exploit this by passing a malicious field value in a raw message to the ActionMessage function.
Affected products
- Apache Struts 2 2.1.x, 2.3.x
Timeline
- 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-10: disclosed