CVE-2012-1592: Apache Struts

High severity, CVSS 8.8. EPSS: 28.6% chance of exploitation in the next 30 days.

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.

Affected products

  • Apache Struts: version 2.0.0 only

Published 2019-12-05. Last modified 2026-06-16.