CVE-2012-0392: Apache Struts

Medium severity, CVSS 6.8. EPSS: 97.5% chance of exploitation in the next 30 days.

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

Affected products

  • Apache Struts: from 2.0.0, before 2.3.1 (fixed in 2.3.1)

Published 2012-01-08. Last modified 2026-06-16.