CVE-2015-1831: Apache Struts

High severity, CVSS 7.5. EPSS: 6.4% chance of exploitation in the next 30 days.

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.

Affected products

  • Apache Struts: version 2.3.20 only

Published 2015-07-16. Last modified 2026-06-17.