Red Hat Bugzilla – Bug 1348251
CVE-2016-4433 struts: Bypassing internal security mechanisms by crafted request
Last modified: 2018-01-30 10:45:00 EST
It is possible to pass a crafted request which can be used to bypass internal security mechanism and manipulate return string which can leads to redirecting user to unvalidated location. Affected versions: Struts 2.3.20 - Struts 2.3.28.1 External References: https://struts.apache.org/docs/s2-039.html
thanks for the information, but I remove from the CC list.