The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.
References
Configurations
History
No history.
Information
Published : 2015-07-16 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-1831
Mitre link : CVE-2015-1831
CVE.ORG link : CVE-2015-1831
JSON object : View
Products Affected
apache
- struts
CWE