{"id":"GHSA-vq79-mgpx-2wx4","summary":"Apache Struts Access Control Redirect","details":"Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.","aliases":["CVE-2016-4431"],"modified":"2023-11-08T03:58:28.565278Z","published":"2022-05-17T02:16:00Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-07-31T22:21:37Z","nvd_published_at":"2016-07-04T22:59:00Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4431"},{"type":"WEB","url":"https://github.com/apache/struts/commit/eccc31ebce5430f9e91b9684c63eaaf885e603f9"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1348252"},{"type":"PACKAGE","url":"https://github.com/apache/struts"},{"type":"WEB","url":"https://struts.apache.org/docs/s2-040.html"},{"type":"WEB","url":"https://web.archive.org/web/20210123145002/http://www.securityfocus.com/bid/91284"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN45093481/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2016-000113"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=ssg1S1009282"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21987854"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html"}],"affected":[{"package":{"name":"org.apache.struts:struts-parent","ecosystem":"Maven","purl":"pkg:maven/org.apache.struts/struts-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.20"},{"fixed":"2.3.29"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.3.28.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vq79-mgpx-2wx4/GHSA-vq79-mgpx-2wx4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}