CVE-2012-0392 describes a critical vulnerability in Apache Struts versions prior to 2.3.1.1, where the CookieInterceptor component fails to properly validate parameter names. This flaw allows remote attackers to execute arbitrary commands by injecting malicious Java code via a crafted HTTP Cookie header. With a CVSS score of 6.8 (medium severity), this vulnerability can lead to partial confidentiality, integrity, and availability compromise due to network-based attacks with medium complexity. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB and Nuclei templates are available, indicating a potential for exploitation, though community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.