PT-2026-72883 · Apache · Apache Struts
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Struts version 7.2.1
Description
A data exposure issue exists in the JSON plugin where per-response serialization state may be shared across concurrent requests. This allows response content from one request to be observed by another. The issue specifically affects the SMD / JSON-RPC handling of the JSON interceptor, which is disabled by default. Applications utilizing the json result type are not impacted.
Recommendations
Upgrade to version 7.3.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Struts