{"id":"CVE-2012-0393","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-0393","summary":"Apache Struts's ParameterInterceptor component does not prevent access to public constructors","details":"The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.","published":"2022-05-04T00:29:43Z","modified":"2024-12-03T06:02:47.456094Z","cvss":null,"epss":{"score":0.37438,"percentile":0.98411,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.struts:struts2-core","fixedVersion":"2.3.1.1"},{"ecosystem":"Maven","name":"org.apache.struts.xwork:xwork-core","fixedVersion":"2.2.3.1"}],"fix":{"url":"https://github.com/apache/struts/commit/25e50069d60434a30395e3a98357ffba2bed427e","label":"apache/struts@25e5006"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-0393"},{"type":"WEB","url":"https://github.com/apache/struts/commit/25e50069d60434a30395e3a98357ffba2bed427e"},{"type":"WEB","url":"https://github.com/apache/struts/commit/9cad25f258bb2629d263f828574d2671366c238d"},{"type":"PACKAGE","url":"https://github.com/apache/struts"},{"type":"WEB","url":"https://web.archive.org/web/20120612142634/https://sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt"},{"type":"WEB","url":"https://web.archive.org/web/20140723153720/http://secunia.com/advisories/47393"},{"type":"WEB","url":"http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html"},{"type":"WEB","url":"http://struts.apache.org/2.x/docs/s2-008.html"},{"type":"WEB","url":"http://struts.apache.org/2.x/docs/version-notes-2311.html"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/18329"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-03T06:02:47.456094Z"}}