CVE-2016-4430
04.07.2016, 22:59
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
Vendor | Product | Version |
---|---|---|
apache | struts | 2.3.20 |
apache | struts | 2.3.20.1 |
apache | struts | 2.3.20.3 |
apache | struts | 2.3.24 |
apache | struts | 2.3.24.1 |
apache | struts | 2.3.24.3 |
apache | struts | 2.3.28 |
apache | struts | 2.3.28.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References