Apache Struts 2 REST Plugin XStream Remote Code Execution

Apache Struts versions 2.5 through 2.5.12 using the REST plugin are vulnerable to a Java deserialization attack in the XStream library.

Leave a Reply