CVE-2014-0094 is a critical vulnerability affecting Apache Struts versions prior to 2.3.16.2. It allows remote attackers to manipulate the ClassLoader via the "class" parameter, leading to potential remote code execution. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N), this vulnerability is easily exploitable over the network with low complexity and no authentication, potentially leading to partial integrity compromise. Exploit code, including Metasploit modules, is publicly available, and the vulnerability has garnered significant community discussion and media coverage, indicating its widespread awareness and potential for exploitation, despite not being on the KEV catalog or currently active on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.16.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.