Description
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vrwc-qjmw-5rjm | ClassLoader manipulation in Apache Struts |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:37.910Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0094
No data.
Status : Deferred
Published: 2014-03-11T13:00:37.107
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0094
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA