Red Hat Bugzilla – Bug 1326720
CVE-2016-0785 struts2: forced double OGNL evaluation on raw input in tag attributes
Last modified: 2016-04-13 12:43:00 EDT
The Apache Struts frameworks when forced, performs double evaluation of attributes' values assigned to certain tags so it is possible to pass in a value that will be evaluated again when a tag's attributes will be rendered. External references: http://struts.apache.org/docs/s2-029.html