REDHAT-BUG-1343540: Input Validation
It was reported that The Apache Struts 1 Validator contains a vulnerability where input validation configurations (validation rules, error messages, etc.) may be modified. This occurs when ValidatorForm and ValidatorActionForm (including its subclasses) are in the session scope.
Affects Apache Struts 1 versions 1.0 through 1.3.10.
External References:
https://jvn.jp/en/jp/JVN65044642/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1343540?
The severity of REDHAT-BUG-1343540 is considered critical due to the risk of unauthorized input validation configuration changes.
How do I fix REDHAT-BUG-1343540?
To fix REDHAT-BUG-1343540, upgrade to a version of Apache Struts 1 that is later than 1.3.10.
What versions of Apache Struts 1 are affected by REDHAT-BUG-1343540?
Apache Struts 1 versions from 1.0 up to and including 1.3.10 are affected by REDHAT-BUG-1343540.
What are the potential risks associated with REDHAT-BUG-1343540?
The risks associated with REDHAT-BUG-1343540 include possible input manipulation leading to application compromise or unexpected behavior.
Is a temporary workaround available for REDHAT-BUG-1343540?
A temporary workaround for REDHAT-BUG-1343540 is to avoid using session-scoped ValidatorForm and ValidatorActionForm until a secure version is applied.