CVE-2016-4431: Input Validation
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.
Other sources
Using existing default method it can be possible to bypass internal security mechanism and manipulate return string which can leads to redirecting user to unvalidated location.
Affected versions: Struts 2.3.20 - Struts 2.3.28.1
External References:
https://struts.apache.org/docs/s2-040.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4431?
CVE-2016-4431 has a high severity rating due to its potential to allow remote attackers to bypass access restrictions.
How do I fix CVE-2016-4431?
To fix CVE-2016-4431, update Apache Struts to version 2.3.29 or later.
What software versions are affected by CVE-2016-4431?
CVE-2016-4431 affects Apache Struts versions 2.3.20 through 2.3.28.1.
What type of attacks can be conducted using CVE-2016-4431?
CVE-2016-4431 can be exploited to conduct redirection attacks by bypassing internal security mechanisms.
Is CVE-2016-4431 related to any specific Apache Struts components?
CVE-2016-4431 is related to the default methods in Apache Struts that can be manipulated to compromise security.