- Description
- Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- struts
CVSS 3.1
- Type
- Secondary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- security@apache.org
- CWE-567
- Hype score
- Not currently trending
Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts #dos https://t.co/8XUCJQetCY
@omokazuki
14 Aug 2026
125 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Apache Strutsで5件の脆弱性(S2-070~S2-074) CVE-2026-73631 CVE-2026-73632 CVE-2026-73633 CVE-2026-73634 CVE-2026-73635 https://t.co/M7OFPs9BmA
@autumn_good_35
14 Aug 2026
617 Impressions
2 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:struts:7.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "5B413DED-A87F-4793-A0DC-7D11B1C7A6BE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]