Candidate: CVE-2016-4433 PublicDate: 2016-07-04 22:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4433 https://struts.apache.org/docs/s2-039.html Description: Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request. Ubuntu-Description: Notes: seth-arnold> The advisory claims "Struts 2.3.20 - Struts Struts 2.3.28.1" but doesn't make positive statements why that range only. Bugs: Priority: medium Discovered-by: Takeshi Terada Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_libstruts1.2-java: upstream_libstruts1.2-java: released (2.3.29) precise_libstruts1.2-java: ignored (reached end-of-life) precise/esm_libstruts1.2-java: DNE (precise was needed) trusty_libstruts1.2-java: ignored (reached end-of-life) trusty/esm_libstruts1.2-java: DNE (trusty was needed) vivid/stable-phone-overlay_libstruts1.2-java: DNE vivid/ubuntu-core_libstruts1.2-java: DNE wily_libstruts1.2-java: DNE xenial_libstruts1.2-java: DNE yakkety_libstruts1.2-java: DNE zesty_libstruts1.2-java: DNE artful_libstruts1.2-java: DNE bionic_libstruts1.2-java: DNE cosmic_libstruts1.2-java: DNE disco_libstruts1.2-java: DNE devel_libstruts1.2-java: DNE