Apache Struts ActionServlet. java XSS Vulnerability (CVE-2016-1182)
Apache Struts ActionServlet. java XSS Vulnerability (CVE-2016-1182)
Release date:
Updated on:
Affected Systems:
Apache Group Struts 1 1.x-1.3.10
Description:
CVE (CAN) ID: CVE-2016-1182
Struts is the open source code used to build Web applications.
In Apache Struts 1 1.x-1.3.10, ActionServlet. java does not properly restrict Validator configurations. Remote attackers can execute cross-site scripting attacks or cause denial-of-service attacks by constructing input.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/kawasima/struts1-forever/commit/eda3a79907ed8fcb0387a0496d0cb14332f250e8
Https://security-tracker.debian.org/tracker/CVE-2016-1182
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1343540
This article permanently updates the link address: