Red Hat Bugzilla – Bug 1260101
CVE-2015-2992 struts: XSS vulnerability when JSP files are exposed to be accessed directly
Last modified: 2016-03-04 06:26:05 EST
Arbitrary script can be executed when JSP files are exposed to be accessed directly. Affected versions are Struts 2.0.0 - 2.3.16.3. External reference: https://struts.apache.org/docs/s2-025.html
Created struts tracking bugs for this issue: Affects: fedora-all [bug 1260104] Affects: epel-7 [bug 1260105]
Affected Software: Struts 2.0.0 - Struts Struts 2.3.16.3