Red Hat Bugzilla – Bug 1222515
CVE-2015-1831 struts2: incorrect default exclude patterns
Last modified: 2015-05-18 08:18:01 EDT
It was found that incorrect default exclude patterns were introduced in the 2.3.20 version of Struts. If the default settings are used, a remote attacker could compromise an internal application's state. External references: http://struts.apache.org/docs/s2-024.html
Statement: Not Vulnerable. This issue only affects struts 2; it does not affect the versions of struts as shipped with various Red Hat products.