Vulnerabilities/

Apache Struts 2 REST plugin XStream RCE S2-052

Impact: High

Description

The REST Plugin is using a XStreamHandler with an instance of XStream for deserialization without any type filtering and this can lead to Remote Code Execution when deserializing XML payloads.

Recommendation

Upgrade to Apache Struts version 2.5.13 or 2.3.34 or newer version.

References

Last updated on June 06, 2022

This issue is available in SmartScanner Professional

See Pricing