Description

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.

Remediation

References

Related Vulnerabilities

Severity

Critical

Tags

Vendor Advisory NVD-CWE-noinfo