Web Hack List

Top 10 winner

Apache Struts ClassLoader Manipulation Remote Code Execution

S2-020 - Apache Struts 2 Documentation

The Struts S2-020 bulletin covers two issues fixed in 2.3.16.1: Commons FileUpload 1.3 allows denial of service, and ParametersInterceptor accepts a class parameter mapped to getClass(), letting a remote attacker manipulate the ClassLoader. The advised remedies are upgrading the library and excluding class from request parameters.

Record

Document
S2-020 - Apache Struts 2 Documentation
Researcher
Lukasz Lenart
Published by
cwiki.apache.org
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Lukasz Lenart, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .