CVE-2014-3540

Description

This CVE is under investigation by Red Hat Product Security.

Statement

MITRE has rejected this CVE ID, favoring the use of CVE-2014-0114.

This flaw was the root cause of CVE-2014-0114, a flaw in Apache Struts 1 that could lead to unauthenticated remote code execution under certains conditions. Other frameworks built on commons-beanutils, such as Apache Stripes, are likely to expose similar issues. commons-beanutils 1.9.2 has now shipped, including a specialized BeanIntrospector implementation that allows suppressing properties. Frameworks built on commons-beantutils can make use of the new pre-configured SuppressPropertiesBeanIntrospector to address this flaw.

Frequently Asked Questions

Want to get errata notifications? Sign up here.