Red Hat Bugzilla – Bug 1331019
CVE-2016-3082 Struts2: XSLTResult can be used to parse arbitrary stylesheet (S2-031)
Last modified: 2016-04-27 09:07:05 EDT
XSLTResult allows for the location of a stylesheet being passed as a request parameter. In some circumstances this can be used to inject remotely executable code. External References: https://struts.apache.org/docs/s2-031.html
Statement: Not Vulnerable. This issue affects Struts 2 only; it does not affect the versions of struts as shipped with various Red Hat products.