Red Hat Bugzilla – Bug 1348252
CVE-2016-4431 struts: Possible manipulation of return result and bypassing validation
Last modified: 2018-01-30 10:45:04 EST
Using existing default method it can be possible to bypass internal security mechanism and manipulate return string which can leads to redirecting user to unvalidated location. Affected versions: Struts 2.3.20 - Struts 2.3.28.1 External References: https://struts.apache.org/docs/s2-040.html
thanks for the information, but I remove from the CC list.