Apache Struts Cross-Site Request Forgery Vulnerability (CVE-2016-4430)
Apache Struts Cross-Site Request Forgery Vulnerability (CVE-2016-4430)
Release date:
Updated on:
Affected Systems:
Apache Group Struts2 2.3.20-2.3.28.1
Description:
CVE (CAN) ID: CVE-2016-4430
Struts2 is an extensible framework for building enterprise-level Jave Web applications.
Apache Struts 2 2.3.20-2.3.28.1 handles token verification errors and has security vulnerabilities. remote attacks can be exploited to perform cross-site request forgery attacks.
<* Source: Takeshi Terada websec02 dot g02 at gmail.com
Link: https://struts.apache.org/docs/s2-038.html
*>
Suggestion:
Vendor patch:
Apache Group
------------
Apache Group has released a Security Bulletin (S2-038) and patches for this:
S2-038: It is possible to bypass token validation and perform a CSRF attack
Link: https://struts.apache.org/docs/s2-038.html
Patch download: https://struts.apache.org/docs/version-notes-2329.html
This article permanently updates the link address: