Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4433.json"