{"id":"GHSA-cx25-xg7c-xfm5","summary":"Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability","details":"** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts.\n\nThis issue affects Apache Struts Extras: before 2.\n\nWhen using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without any filtering. Specially-crafted input may lead to log output where part of the message masquerades as a separate log line, confusing consumers of the logs (either human or automated). \n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","aliases":["CVE-2025-54656"],"modified":"2025-11-14T23:09:54.325221Z","published":"2025-07-30T18:31:36Z","database_specific":{"github_reviewed_at":"2025-07-30T20:02:07Z","nvd_published_at":"2025-07-30T16:15:28Z","cwe_ids":["CWE-117"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54656"},{"type":"PACKAGE","url":"https://github.com/apache/struts"},{"type":"WEB","url":"https://lists.apache.org/thread/so5cn07j2zn9vlf1xnfqp630wts719rr"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/07/30/1"}],"affected":[{"package":{"name":"org.apache.struts:struts-extras","ecosystem":"Maven","purl":"pkg:maven/org.apache.struts/struts-extras"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.10"}]}],"versions":["1.3.10","1.3.5","1.3.8","1.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-cx25-xg7c-xfm5/GHSA-cx25-xg7c-xfm5.json"}},{"package":{"name":"struts:struts","ecosystem":"Maven","purl":"pkg:maven/struts/struts"},"versions":["1.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-cx25-xg7c-xfm5/GHSA-cx25-xg7c-xfm5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}