Bugzilla – Bug 931428
VUL-0: CVE-2015-1831: struts2: incorrect default exclude patterns
Last modified: 2015-05-19 08:45:48 UTC
This bug was only created for CVE reference. rh#1222515 / CVE-2015-1831 --------------------------------- It was found that incorrect default exclude patterns were introduced in the 2.3.20 version of Struts. If the default settings are used, a remote attacker could compromise an internal application's state. Statement: Not Vulnerable. This issue only affects struts 2; it does not affect the versions of struts as shipped with various Red Hat products. --------------------------------- The same statement goes for SUSE products. Only struts 1 is currently in use. References: http://struts.apache.org/docs/s2-024.html https://bugzilla.redhat.com/show_bug.cgi?id=1222515 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1831 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1831
Closing.