CVE-2012-0392: Apache Struts
Medium severity, CVSS 6.8. EPSS: 97.5% chance of exploitation in the next 30 days.
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
Affected products
- Apache Struts: from 2.0.0, before 2.3.1 (fixed in 2.3.1)
Published 2012-01-08. Last modified 2026-06-16.