Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • T ticket
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1,809
    • Issues 1,809
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 0
    • Merge requests 0
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • Administrator
  • ticket
  • Issues
  • #1818

Closed
Open
Created Mar 14, 2024 by Administrator@rootMaintainer

Findings for SCA, Critical, [TheRedHatter/javagoof:todolist-web-struts/pom.xml]:Arbitrary Command Execution

Created by: armorcodegithubpreprod[bot]

Findings for SCA, Critical, [TheRedHatter/javagoof:todolist-web-struts/pom.xml]:Arbitrary Command Execution

Component Details

  • Exploit Maturity: mature
  • Vulnerable Package: -
  • Current Version: -
  • Vulnerable Version(s): >[2,2.3.20.2),[2.3.24,2.3.24.3),[2.3.28,2.3.28.1)
  • Vulnerable Path: >null

Overview

org.apache.struts:struts2-core Apache Struts 2.3.20.x before 2.3.20.3, 2.3.24.x before 2.3.24.3, and 2.3.28.x before 2.3.28.1, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

References

  • NVD Snyk Project Status: Active


Assignee
Assign to
Time tracking