In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.struts:struts2-core(Maven) | 2.0.1 | 2.3.34 | N/A |
| org.apache.struts:struts2-core(Maven) | 2.5.0 | 2.5.11 | N/A |
CVSS Metrics