Red Hat Bugzilla – Bug 1172133
CVE-2014-7809 struts2: predictable generation of form submission token
Last modified: 2014-12-10 03:04:32 EST
It was found that the Struts 2 Random Number Generator component generates predictable form submission tokens. A remote attacker able to acquire a victim's form submission token could predict the next value of this token and perform Cross-Site Request Forgery (CSRF) attacks against that victim. This flaw is reported to affect Struts 2.0.0 through 2.3.16.3. It is corrected in Struts 2.3.20. External References: https://cwiki.apache.org/confluence/display/WW/S2-023
Statement: Not Vulnerable. This issue only affects struts 2; it does not affect the versions of struts as shipped with various Red Hat products.