Disclosure summary
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-01-21T00:00:00-05:00
MODIFIED 2022-01-21T00:00:00-05:00
INGESTED 2026-10-06T11:42:59-04:00