oss-sec mailing list archives

Re: CVE request: Struts2 xsltResult local code execution flaw


From: Kurt Seifried <kseifried () redhat com>
Date: Wed, 28 Mar 2012 08:54:05 -0600

On 03/27/2012 11:29 PM, David Jorm wrote:
A local code execution flaw has been identified in Struts2. I cannot find a CVE ID for it anywhere.

Original report: http://seclists.org/bugtraq/2012/Mar/110
OSVDB: http://osvdb.org/80547
X-Force: http://xforce.iss.net/xforce/xfdb/74319

Thanks

Please use CVE-2012-1592 for this issue.

-- 
Kurt Seifried Red Hat Security Response Team (SRT)


Current thread: