FlawAtlas
Search the atlas
CVE-2013-4316 High

Code injection in Apache Struts

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

Exploit probability 8.3%
Published May 17, 2022
Required by Not available
Last source change December 6, 2024

02 / AFFECTED SOFTWARE

Affected packages

Maven org.apache.struts:struts2-core

32 explicit affected versions

Maven org.apache.struts:struts2-rest-plugin

23 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-j7h6-xr7g-m2c5

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

View original source

05 / REFERENCES

Further evidence