Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-737w-mh58-cxjp] Arbitrary code execution in Apache Struts #3160

Conversation

sunSUNQ
Copy link

@sunSUNQ sunSUNQ commented Dec 25, 2023

Updates

  • References

Comments
Add some patch links related to CVE-2013-1966 which fixed in multi-branch.

@github-actions github-actions bot changed the base branch from main to sunSUNQ/advisory-improvement-3160 December 25, 2023 09:41
@shelbyc
Copy link
Contributor

shelbyc commented Dec 27, 2023

Hi @sunSUNQ, I added apache/struts@7e6f641 as a reference link because https://cwiki.apache.org/confluence/display/WW/S2-013 mentions working with the constant struts.ognl.enableOGNLEvalExpression that was added in this commit. I wasn't able to confirm that the other commits are related to this CVE. I also set the vulnerable version range to >= 2.0.0, < 2.3.14.2 because the Jira ticket mentions that only versions in the 2.x branch are vulnerable. Thank you for your contribution!

@advisory-database advisory-database bot merged commit e80b363 into sunSUNQ/advisory-improvement-3160 Dec 27, 2023
2 checks passed
@advisory-database advisory-database bot deleted the sunSUNQ-GHSA-737w-mh58-cxjp branch December 27, 2023 21:53
@advisory-database
Copy link
Contributor

Hi @sunSUNQ! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants