Description
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
Remediation
References
http://struts.apache.org/docs/s2-033.html
http://www.securityfocus.com/bid/90960
http://www.securitytracker.com/id/1036017
http://www-01.ibm.com/support/docview.wss?uid=swg21987854
https://www.exploit-db.com/exploits/39919/
Related Vulnerabilities
CVE-2020-1723 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2020-11988 Vulnerability in maven package org.apache.xmlgraphics:xmlgraphics-commons
CVE-2017-5641 Vulnerability in maven package org.apache.flex.blazeds:flex-messaging-core
CVE-2023-30524 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2020-2182 Vulnerability in maven package org.jenkins-ci.plugins:credentials-binding