Description
Possible Remote Code Execution attack when using the Struts REST plugin with XStream handler to handle XML payloads.
Remediation
Upgrade to Struts 2.5.13 or Struts 2.3.34.
References
Related Vulnerabilities
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5741)
Jenkins Improper Authentication Vulnerability (CVE-2014-2066)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-1551)
Oracle Database Server CVE-2015-0483 Vulnerability (CVE-2015-0483)