A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. A patch exists as of version 2.5.22.
{
"github_reviewed_at": "2022-07-13T19:27:31Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-434"
],
"nvd_published_at": "2019-12-05T21:15:00Z",
"severity": "HIGH"
}