Bug 28083 - struts security issue CVE-2020-17530
Summary: struts security issue CVE-2020-17530
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-01-13 15:45 CET by Zombie Ryushu
Modified: 2021-01-13 17:47 CET (History)
0 users

See Also:
Source RPM: struts-1.3.10-19.mga7.src.rpm
CVE: CVE-2020-17530
Status comment:


Attachments

Description Zombie Ryushu 2021-01-13 15:45:31 CET
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Zombie Ryushu 2021-01-13 15:52:48 CET

CVE: (none) => CVE-2020-17530

Comment 1 David Walser 2021-01-13 17:47:46 CET
Clearly 1.3.10 is not between 2.0.0 and 2.5.25.

Resolution: (none) => INVALID
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.