ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
{ "github_reviewed_at": "2022-11-03T22:57:46Z", "severity": "HIGH", "cwe_ids": [], "github_reviewed": true, "nvd_published_at": "2014-04-29T10:37:00Z" }