Loading HuntDB...

Apache Struts 1 Improper Input Validation Vulnerability

Added Feb. 10, 2022 Due Aug. 10, 2022 CVE-2017-9791
Overdue Apache / Struts 1 CWE-20

Description

The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
7 months, 3 weeks ago