First published: Tue Jun 07 2016(Updated: )
It was reported that The Apache Struts 1 Validator contains a vulnerability where input validation configurations (validation rules, error messages, etc.) may be modified. This occurs when ValidatorForm and ValidatorActionForm (including its subclasses) are in the session scope. Affects Apache Struts 1 versions 1.0 through 1.3.10. External References: <a href="https://jvn.jp/en/jp/JVN65044642/">https://jvn.jp/en/jp/JVN65044642/</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Struts | >=1.0<1.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1343540 is considered critical due to the risk of unauthorized input validation configuration changes.
To fix REDHAT-BUG-1343540, upgrade to a version of Apache Struts 1 that is later than 1.3.10.
Apache Struts 1 versions from 1.0 up to and including 1.3.10 are affected by REDHAT-BUG-1343540.
The risks associated with REDHAT-BUG-1343540 include possible input manipulation leading to application compromise or unexpected behavior.
A temporary workaround for REDHAT-BUG-1343540 is to avoid using session-scoped ValidatorForm and ValidatorActionForm until a secure version is applied.