CVE-2016-4433: Input Validation
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
Other sources
It is possible to pass a crafted request which can be used to bypass internal security mechanism and manipulate return string which can leads to redirecting user to unvalidated location.
Affected versions: Struts 2.3.20 - Struts 2.3.28.1
External References:
https://struts.apache.org/docs/s2-039.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4433?
CVE-2016-4433 is classified as a medium severity vulnerability that allows attackers to bypass access restrictions.
How do I fix CVE-2016-4433?
To fix CVE-2016-4433, update Apache Struts to version 2.3.29 or later.
Which versions of Apache Struts are affected by CVE-2016-4433?
CVE-2016-4433 affects Apache Struts versions 2.3.20 through 2.3.28.1.
What types of attacks can CVE-2016-4433 facilitate?
CVE-2016-4433 can facilitate redirection attacks by allowing crafted requests to bypass intended security mechanisms.
What are the risks associated with CVE-2016-4433?
The risks associated with CVE-2016-4433 include unauthorized access and the potential manipulation of application behavior by attackers.