Bugzilla – Bug 975279
VUL-0: CVE-2016-4003: struts: Cross-site scripting (XSS) vulnerability in the URLDecoder functio
Last modified: 2016-04-22 08:36:27 UTC
CVE-2016-4003 Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4003 https://issues.apache.org/jira/browse/WW-4507 http://www.securitytracker.com/id/1035268 http://struts.apache.org/docs/s2-028.html
bugbot adjusting priority
so since there are not calls to those functions the package is not affected by this CVE (still could be vulnerable)