Beveiligingsadvies

CVE-2017-9791

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-07-10 16:00:00
Laatst bijgewerkt 2025-10-21 23:55:38
Toegewezen door apache
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.