Top 10 winner
Apache Struts ClassLoader Manipulation Remote Code Execution
The Struts S2-020 bulletin covers two issues fixed in 2.3.16.1: Commons FileUpload 1.3 allows denial of service, and ParametersInterceptor accepts a class parameter mapped to getClass(), letting a remote attacker manipulate the ClassLoader. The advised remedies are upgrading the library and excluding class from request parameters.
Record
- Researcher
- Lukasz Lenart
- Published by
- cwiki.apache.org
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Lukasz Lenart, first published at the original source. Preserved copies are kept so the citation survives its host.