CVE-2016-3090: Apache Struts
High severity, CVSS 8.8. EPSS: 5.7% chance of exploitation in the next 30 days.
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
Affected products
- Apache Struts: version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; version 2.0.6 only; …
Published 2017-10-30. Last modified 2026-06-17.