MGASA-2016-0244

Source
https://advisories.mageia.org/MGASA-2016-0244.html
Import Source
https://advisories.mageia.org/MGASA-2016-0244.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0244
Related
Published
2016-07-08T19:50:50Z
Modified
2016-07-08T19:38:01Z
Summary
Updated struts packages fix security vulnerabilities
Details

Updated struts packages fix security vulnerabilities:

A vulnerability in Apache Struts 1 ActionForm allowing unintended remote operations against components on server memory, such as Servlets and ClassLoader, was found (CVE-2016-1181).

It was reported that The Apache Struts 1 Validator contains a vulnerability where input validation configurations (validation rules, error messages, etc.) may be modified. This occurs when ValidatorForm and ValidatorActionForm (including its subclasses) are in the session scope (CVE-2016-1182).

References
Credits

Affected packages

Mageia:5 / struts

Package

Name
struts
Purl
pkg:rpm/mageia/struts?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.10-8.2.mga5

Ecosystem specific

{
    "section": "core"
}