CVE-2016-3082

Source
https://cve.org/CVERecord?id=CVE-2016-3082
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3082.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-3082
Aliases
Published
2016-04-26T14:59:03.190Z
Modified
2026-04-10T03:50:50.745449Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.

References

Affected packages

Git / github.com/apache/struts

Affected ranges

Type
GIT
Repo
https://github.com/apache/struts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.9"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.10"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.11"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.11.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.11.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.13"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.14"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.8.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.1.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.3.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.1.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.1.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.4.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.14"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.14.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.14.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.14.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.15"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.15.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.15.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.15.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.16"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.16.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.16.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.16.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.20"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.20.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.24"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.24.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.28"
        }
    ]
}

Affected versions

Other
STRUTS_2_0_0
STRUTS_2_0_1
STRUTS_2_0_10
STRUTS_2_0_11
STRUTS_2_0_11_1
STRUTS_2_0_11_2
STRUTS_2_0_12
STRUTS_2_0_13
STRUTS_2_0_14
STRUTS_2_0_2
STRUTS_2_0_3
STRUTS_2_0_4
STRUTS_2_0_5
STRUTS_2_0_6
STRUTS_2_0_7
STRUTS_2_0_8
STRUTS_2_0_9
STRUTS_2_1_0
STRUTS_2_1_1
STRUTS_2_1_2
STRUTS_2_1_3
STRUTS_2_1_4
STRUTS_2_1_5
STRUTS_2_1_6
STRUTS_2_1_8
STRUTS_2_1_8_1
STRUTS_2_2_1
STRUTS_2_2_1_1
STRUTS_2_2_3
STRUTS_2_2_3_1
STRUTS_2_3_1
STRUTS_2_3_12
STRUTS_2_3_14
STRUTS_2_3_14_1
STRUTS_2_3_14_2
STRUTS_2_3_14_3
STRUTS_2_3_15
STRUTS_2_3_15_1
STRUTS_2_3_15_2
STRUTS_2_3_15_3
STRUTS_2_3_16
STRUTS_2_3_16_1
STRUTS_2_3_16_2
STRUTS_2_3_16_3
STRUTS_2_3_1_1
STRUTS_2_3_1_2
STRUTS_2_3_20
STRUTS_2_3_20_1
STRUTS_2_3_24
STRUTS_2_3_24_1
STRUTS_2_3_25
STRUTS_2_3_26
STRUTS_2_3_27
STRUTS_2_3_28
STRUTS_2_3_3
STRUTS_2_3_4
STRUTS_2_3_4_1
STRUTS_2_3_7
STRUTS_2_3_8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3082.json"