CVE-2014-0116
Publication date 8 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libstruts1.2-java | 14.04 LTS trusty | Not in release |