Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
The product accepts XML from an untrusted source but does not validate the XML against the proper schema.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Struts | Apache | 2.0.0 (including) | 2.3.37 (including) |
| Struts | Apache | 2.5.0 (including) | 2.5.33 (including) |
| Struts | Apache | 6.0.0 (including) | 6.1.1 (excluding) |