Red Hat Bugzilla – Bug 1026148
CVE-2013-6348 Apache Struts2: XSS via malicious action parameter
Last modified: 2016-03-04 06:32:36 EST
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts2 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to actionNames.action and showConfig.action in config-browser/. Affects: Versions >=2.0.0 and <=2.3.15.3 Fixed In: 2.3.16 Upstream Bug: https://issues.apache.org/jira/browse/WW-4213 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6348 http://seclists.org/fulldisclosure/2013/Oct/244 http://en.wooyun.org/bugs/wooyun-2013-034?2592 http://packetstormsecurity.com/files/123805/Struts-2.3.15.3-Cross-Site-Scripting.html http://osvdb.org/99047 http://osvdb.org/99048
Statement: Not Vulnerable. This issue only affects struts 2, it does not affect the versions of struts as shipped with various Red Hat products.