CVE-2015-5169 - Medium Severity Vulnerability
Vulnerable Library - struts2-core-2.3.1.2.jar
Apache Struts 2
Path to dependency file: /tmp/ws-scm/Struts2Example/pom.xml
Path to vulnerable library: 20200325141938/downloadResource_d50070f4-1279-48e5-8366-a2fcdc735d7c/20200325145151/struts2-core-2.3.1.2.jar
Dependency Hierarchy:
- ❌ struts2-core-2.3.1.2.jar (Vulnerable Library)
Found in HEAD commit: 20d7b6df1b42979ec0033b63405d552a70d92b0c
Vulnerability Details
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Publish Date: 2017-09-25
URL: CVE-2015-5169
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5169
Release Date: 2017-09-25
Fix Resolution: 2.3.20
CVE-2015-5169 - Medium Severity Vulnerability
Apache Struts 2
Path to dependency file: /tmp/ws-scm/Struts2Example/pom.xml
Path to vulnerable library: 20200325141938/downloadResource_d50070f4-1279-48e5-8366-a2fcdc735d7c/20200325145151/struts2-core-2.3.1.2.jar
Dependency Hierarchy:
Found in HEAD commit: 20d7b6df1b42979ec0033b63405d552a70d92b0c
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Publish Date: 2017-09-25
URL: CVE-2015-5169
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5169
Release Date: 2017-09-25
Fix Resolution: 2.3.20