Red Hat Bugzilla – Bug 985123
CVE-2013-2135 Apache Struts 2 arbitrary OGNL code execution via double evaluation
Last modified: 2013-07-19 03:51:24 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2135 to the following vulnerability: Name: CVE-2013-2135 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2135 Assigned: 20130219 Reference: https://cwiki.apache.org/confluence/display/WW/S2-015 Reference: http://struts.apache.org/development/2.x/docs/s2-015.html Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
Upstream bug: https://issues.apache.org/jira/browse/WW-4090 Upstream commit: https://svn.apache.org/viewvc?view=revision&revision=r1490149
Statement: Not Vulnerable. This issue only affects struts 2, it does not affect the versions of struts as shipped with various Red Hat products.