REDHAT-BUG-2428559: High severity Apache Struts vulnerability
Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Strutsto a version that resolves this vulnerability.Fixed in 6.1.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2428559?
The severity of REDHAT-BUG-2428559 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2428559?
To fix REDHAT-BUG-2428559, users should upgrade to Apache Struts version 6.1.1 or later.
What is the impact of REDHAT-BUG-2428559?
REDHAT-BUG-2428559 presents a Missing XML Validation vulnerability in Apache Struts that could be exploited by attackers.
Which versions of Apache Struts are affected by REDHAT-BUG-2428559?
The affected versions of Apache Struts are from 2.0.0 before 2.2.1 and from 2.2.1 through 6.1.0.
When was REDHAT-BUG-2428559 published?
REDHAT-BUG-2428559 was published on January 11, 2026.