CVE-2013-4310: Apache Struts
Medium severity, CVSS 5.8. EPSS: 6.5% chance of exploitation in the next 30 days.
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
Affected products
- Apache Struts: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …
Published 2013-09-30. Last modified 2026-06-16.