CVE-2014-0112 is a critical remote code execution vulnerability affecting Apache Struts versions prior to 2.3.20. It allows unauthenticated attackers to manipulate the ClassLoader via a crafted request due to improper access restrictions in the ParametersInterceptor, building on an incomplete fix for a previous vulnerability. With a CVSS score of 7.5 and an EPSS score indicating high exploitability, this flaw poses a significant risk. Exploit code is publicly available through Metasploit modules and ExploitDB, demonstrating its ease of exploitation. While not currently on the CISA KEV catalog, its high FAUCET Risk Score and past media coverage highlight its historical importance and potential for impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.16.2CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.