ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [],
"nvd_published_at": "2014-04-29T10:37:00Z",
"github_reviewed_at": "2022-11-03T22:57:46Z"
}