Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 May 2025 14:45:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 04:45:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T00:23:39.916Z

Reserved: 2012-01-08T00:00:00

Link: CVE-2011-5057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-01-08T17:55:00.903

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-5057

cve-icon Redhat

Severity : Moderate

Publid Date: 2011-12-21T00:00:00Z

Links: CVE-2011-5057 - Bugzilla

cve-icon OpenCVE Enrichment

No data.