CVE-2014-0112

EPSS 91.5%

ClassLoader manipulation in Apache Struts

Published: 5/14/2022Modified: 12/6/2024

Description

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.

Affected packages (1)

References (11)