CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
{
"nvd_published_at": "2014-04-29T10:37:00Z",
"severity": "HIGH",
"github_reviewed_at": "2022-11-03T22:53:53Z",
"github_reviewed": true,
"cwe_ids": []
}