Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
                
            References
                    | Link | Resource | 
|---|---|
| http://jvn.jp/en/jp/JVN45093481/index.html | Vendor Advisory | 
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000111 | VDB Entry Vendor Advisory | 
| https://struts.apache.org/docs/s2-038.html | Vendor Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=1348249 | Issue Tracking | 
| http://www-01.ibm.com/support/docview.wss?uid=ssg1S1009282 | Third Party Advisory | 
| http://www-01.ibm.com/support/docview.wss?uid=swg21987854 | Third Party Advisory | 
| http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html | |
| http://www.securityfocus.com/bid/91281 | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2016-07-04 15:59
Updated : 2017-10-30 18:29
NVD link : CVE-2016-4430
Mitre link : CVE-2016-4430
JSON object : View
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
Products Affected
                apache
- struts
 


