ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
{
    "nvd_published_at": "2014-04-29T10:37:00Z",
    "severity": "HIGH",
    "github_reviewed_at": "2022-11-03T22:57:46Z",
    "github_reviewed": true,
    "cwe_ids": []
}