Apache Struts REST plug-in Arbitrary Code Execution Vulnerability (CVE-2016-4438)
Apache Struts REST plug-in Arbitrary Code Execution Vulnerability (CVE-2016-4438)
Release date:
Updated on:
Affected Systems:
Apache Group Struts2 2.3.20-2.3.28.1
Description:
CVE (CAN) ID: CVE-2016-4438
Struts2 is an extensible framework for building enterprise-level Jave Web applications.
Apache Struts 2 2.3.20-2.3.28.1 has a security vulnerability in the REST plug-in. Remote attackers can execute arbitrary code by constructing expressions.
<* Source: Shinsaku Nomura nomura
Chao Jack PKAV _ vanilla jc1990999
Link: https://struts.apache.org/docs/s2-037.html
*>
Suggestion:
Vendor patch:
Apache Group
------------
Apache Group has released a Security Bulletin (S2-037) and patches for this:
S2-037: Remote Code Execution can be installed med when using REST Plugin.
Link: https://struts.apache.org/docs/s2-037.html
Patch download: https://struts.apache.org/docs/version-notes-2329.html
This article permanently updates the link address: