漏洞描述
In Struts 2 before 2.3.15.1 the information following "action:", "redirect:", or "redirectAction:" is not properly sanitized and will be evaluated as an OGNL expression against the value stack. This introduces the possibility to inject server side code.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
struts.apache.orghttp://struts.apache.org/release/2.3.x/docs/s2-016.html↗cwiki.apache.orghttps://cwiki.apache.org/confluence/display/WW/S2-016↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2013-2251↗archiva.apache.orghttp://archiva.apache.org/security.html↗cxsecurity.comhttp://cxsecurity.com/issue/WLB-2014010087↗