CVE-2016-3090: Input Validation
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
Other sources
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3090?
CVE-2016-3090 is considered critical due to its potential for remote code execution.
How do I fix CVE-2016-3090?
To fix CVE-2016-3090, upgrade Apache Struts to version 2.3.20 or later.
What versions of Apache Struts are affected by CVE-2016-3090?
CVE-2016-3090 affects Apache Struts versions from 2.0.1 through 2.3.19.
Can CVE-2016-3090 be exploited without authentication?
Yes, CVE-2016-3090 can be exploited remotely without requiring authentication.
What impact does CVE-2016-3090 have on affected systems?
The impact of CVE-2016-3090 on affected systems can be severe, allowing attackers to execute arbitrary code.