Executive brief
The REST Plugin in Apache Struts uses an XStreamHandler for deserialization without proper type filtering. This vulnerability allows remote attackers to execute arbitrary code by sending specially crafted XML payloads.
Affected products
- Apache Struts REST Plugin 2.1.1 through 2.3.33, 2.5.x before 2.5.13
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed