Description
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.
Remediation
References
http://www.securityfocus.com/bid/75940
http://www.securitytracker.com/id/1032985
https://struts.apache.org/docs/s2-024.html
Related Vulnerabilities
CVE-2021-46363 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2022-22979 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-parent
CVE-2023-38509 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2017-1000034 Vulnerability in maven package com.typesafe.akka:akka-actor_2.12
CVE-2012-3544 Vulnerability in maven package org.apache.tomcat:tomcat-coyote