CVE-2014-7809
Publication date 10 December 2014
Last updated 24 July 2024
Ubuntu priority
Description
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libstruts1.2-java | ||
| 14.04 LTS trusty | Not in release | |