CVE-2011-5057 describes a vulnerability in Apache Struts 2.3.1.2 and earlier, and versions 2.3.19-2.3.23, where certain interfaces (e.g., SessionAware, RequestAware) do not adequately restrict access to collections like session and request data. This allows remote attackers to modify run-time data values through crafted parameters. With a CVSS score of 5.0 (medium severity), this vulnerability has a low attack complexity and requires no authentication, potentially leading to unauthorized information modification. While the vendor disputes its significance due to an easy workaround, an exploit for session tampering in older Struts versions exists on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.3CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.