CVE-2012-4387

EPSS 7.9%

Denial of service in Apache Struts

Published: 5/17/2022Modified: 12/6/2024

Description

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.

Affected packages (1)

References (9)