Candidate: CVE-2016-4436 PublicDate: 2016-10-03 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4436 https://struts.apache.org/docs/s2-035.html Description: Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up. Ubuntu-Description: Notes: seth-arnold> The advisory says "Struts 2.0.0 - Struts 2.3.28.1" is affected but doesn't make a positive statement why those bounds. Bugs: Priority: medium Discovered-by: Alvaro Munoz Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libstruts1.2-java: upstream_libstruts1.2-java: released (2.3.29, 2.5.1) precise_libstruts1.2-java: ignored (reached end-of-life) precise/esm_libstruts1.2-java: DNE (precise was needed) trusty_libstruts1.2-java: ignored (reached end-of-life) trusty/esm_libstruts1.2-java: DNE (trusty was needed) vivid/stable-phone-overlay_libstruts1.2-java: DNE vivid/ubuntu-core_libstruts1.2-java: DNE wily_libstruts1.2-java: DNE xenial_libstruts1.2-java: DNE yakkety_libstruts1.2-java: DNE zesty_libstruts1.2-java: DNE artful_libstruts1.2-java: DNE bionic_libstruts1.2-java: DNE cosmic_libstruts1.2-java: DNE disco_libstruts1.2-java: DNE devel_libstruts1.2-java: DNE