The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to compromise internal state of an application via unspecified vectors.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Struts |
Apache |
2.3.20 (including) |
2.3.20 (including) |
References