Red Hat Bugzilla – Bug 1348249
CVE-2016-4430 struts: Bypassing token validation triggered by malicious expression
Last modified: 2018-01-30 10:44:57 EST
It was found that it is possible to pass a malicious expression which can be used to bypass token validation and perform CSRF attack. External References: https://struts.apache.org/docs/s2-038.html
thanks for the information, but I remove from the CC list.