• CVE-2012-0392

发布时间: 2022年7月30日

修改时间: 2022年7月30日

概要

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

CVSS v3 指标

NVD openEuler
CVSS评分 6.8 9.3
Attack Vector Network Local
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-1707 The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method. 2022年7月30日

影响产品

产品 状态
KY3.4-4A struts Unaffected
KY3.4-5 struts Unaffected
KY3.5.1 struts Unaffected