{"id":"CVE-2014-0116","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-0116","summary":"ClassLoader manipulation in Apache Struts","details":"CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to \"manipulate\" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.","published":"2022-05-14T00:54:14Z","modified":"2024-12-06T05:43:03.047253Z","cvss":null,"epss":{"score":0.06569,"percentile":0.93485,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.struts:struts2-core","fixedVersion":"2.3.20"}],"fix":{"url":"https://github.com/apache/struts/commit/1a668af7f1ffccea4a3b46d8d8c1fe1c7331ff02","label":"apache/struts@1a668af"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0116"},{"type":"WEB","url":"https://github.com/apache/struts/commit/1a668af7f1ffccea4a3b46d8d8c1fe1c7331ff02"},{"type":"PACKAGE","url":"https://github.com/apache/struts"},{"type":"WEB","url":"http://struts.apache.org/release/2.3.x/docs/s2-022.html"},{"type":"WEB","url":"http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:43:03.047253Z"}}