Back

CRITICAL KEV

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix

Published Jul 18, 2013 ·Due Apr 15, 2022

Description

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 18, 2013
Updated Oct 22, 2025
Reserved Feb 19, 2013
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-47QP-8V9G-39HP