{"id":5091377,"name":"org.apache.struts:struts2-core","ecosystem":"maven","description":"Apache Struts","homepage":"https://struts.apache.org/","licenses":"The Apache Software License, Version 2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/apache/struts","keywords_array":[],"namespace":"org.apache.struts","versions_count":110,"first_release_published_at":"2007-02-10T01:51:42.000Z","latest_release_published_at":"2026-08-12T02:36:27.000Z","latest_release_number":"7.3.0","last_synced_at":"2026-09-24T20:18:00.386Z","created_at":"2022-07-29T08:26:48.544Z","updated_at":"2026-09-25T19:17:02.579Z","registry_url":"https://central.sonatype.com/artifact/org.apache.struts/struts2-core/","install_command":null,"documentation_url":"https://appdoc.app/artifact/org.apache.struts/struts2-core/","metadata":{"repositories":["https://repository.apache.org/snapshots"]},"repo_metadata":{"id":13243842,"uuid":"15928650","full_name":"apache/struts","owner":"apache","description":"Apache Struts is a free, open-source, MVC framework for creating elegant, modern Java web applications","archived":false,"fork":false,"pushed_at":"2026-09-18T06:59:57.000Z","size":88182,"stargazers_count":1368,"open_issues_count":7,"forks_count":869,"subscribers_count":120,"default_branch":"main","last_synced_at":"2026-09-18T14:38:02.083Z","etag":null,"topics":["java","struts","web-framework"],"latest_commit_sha":null,"homepage":"https://struts.apache.org/","language":"Java","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/apache.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":"THREAT_MODEL.md","audit":null,"citation":null,"codeowners":"CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","claude":"CLAUDE.md","gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null}},"created_at":"2014-01-15T08:00:08.000Z","updated_at":"2026-09-18T11:00:35.000Z","dependencies_parsed_at":"2026-09-11T08:14:51.573Z","dependency_job_id":null,"html_url":"https://github.com/apache/struts","commit_stats":{"total_commits":6844,"total_committers":122,"mean_commits":56.09836065573771,"dds":0.6168907071887785,"last_synced_commit":"9aa41f18aeca535cf2f45d00d16a8dabd7e70f87"},"previous_names":[],"tags_count":184,"template":false,"template_full_name":null,"purl":"pkg:github/apache/struts","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/apache","download_url":"https://codeload.github.com/apache/struts/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/sbom","scorecard":{"id":201686,"data":{"date":"2025-08-16T02:10:54Z","repo":{"name":"github.com/apache/struts","commit":"aaa4984eac5d75cc80d7bba225cdeda996280445"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":8.5,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Code-Review","score":0,"reason":"Found 0/2 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:38","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:39","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards-analysis.yaml:39","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards-analysis.yaml:37","Warn: topLevel 'security-events' permission set to 'write': .github/workflows/codeql.yml:27","Info: topLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:28","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:29","Info: topLevel permissions set to 'read-all': .github/workflows/maven.yml:25","Info: topLevel permissions set to 'read-all': .github/workflows/scorecards-analysis.yaml:26","Info: topLevel permissions set to 'read-all': .github/workflows/sonar.yml:24","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":3,"reason":"dependency not pinned by hash detected -- score normalized to 3","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/maven.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/maven.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scorecards-analysis.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/scorecards-analysis.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonar.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/sonar.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonar.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/struts/sonar.yml/main?enable=pin","Info:   2 out of  12 GitHub-owned GitHubAction dependencies pinned","Info:   1 out of   1 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":5,"reason":"badge detected: Passing","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: OSSFuzz integration found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"SAST","score":10,"reason":"SAST tool detected","details":["Info: SAST configuration detected: CodeQL","Info: SAST configuration detected: Sonar","Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"CI-Tests","score":10,"reason":"12 out of 12 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"Contributors","score":10,"reason":"project has 20 contributing companies or organizations","details":["Info: found contributions from: CodeforLeipzig, amazon, apache, atlassian, atlassian-labs, cyberlogic-consulting, expedia, google, grobmeier solutions gmbh, grobmeier-solutions, i'm open to new opportunities, jekyll, opendi, peopleware, redis, softwaremill, struts-community-plugins, timeandbill, van-meter, yaas arghavani system engineering"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-16T22:56:27.020Z","repository_id":13243842,"created_at":"2025-08-16T22:56:27.021Z","updated_at":"2025-08-16T22:56:27.021Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":341189360,"owners_count":37457523,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-18T02:00:15.364Z","response_time":89,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"apache","name":"The Apache Software Foundation","uuid":"47359","kind":"organization","description":"","email":null,"website":"https://www.apache.org/","location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/47359?v=4","repositories_count":3155,"last_synced_at":"2026-09-21T00:26:47.795Z","metadata":{"has_sponsors_listing":false,"funding":null},"html_url":"https://github.com/apache","funding_links":[],"total_stars":1407023,"followers":24310,"following":0,"created_at":"2022-11-02T16:23:23.532Z","updated_at":"2026-09-21T00:26:47.809Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/apache","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/apache/repositories"},"tags":[{"name":"STRUTS_7_3_0","sha":"a88fd76364b8a88a8769455675ceeb8acd256d5b","kind":"tag","published_at":"2026-08-01T13:24:51.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_3_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_3_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_3_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_3_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_3_0/manifests"},{"name":"STRUTS_6_11_0","sha":"52628432a922c87dcbb87241b0f749ee5cfc489f","kind":"tag","published_at":"2026-08-01T10:28:19.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_11_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_11_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_11_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_11_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_11_0/manifests"},{"name":"STRUTS_7_2_1","sha":"8e31112c0bd53f4b27571f557777c06e0666f6e0","kind":"tag","published_at":"2026-06-15T10:31:15.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_2_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_2_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_2_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_2_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_2_1/manifests"},{"name":"STRUTS_7_2_0","sha":"8e908137d03bb148595a9b1f800e2a1ba0393ae8","kind":"tag","published_at":"2026-06-14T17:33:08.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_2_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_2_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_2_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_2_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_2_0/manifests"},{"name":"STRUTS_6_10_0","sha":"4bfbfeb239dde49c55d852bc9ed23fa9bd433eab","kind":"tag","published_at":"2026-05-25T15:19:53.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_10_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_10_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_10_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_10_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_10_0/manifests"},{"name":"STRUTS_6_9_0","sha":"1b2f1857d0ddaef603f5a22bb0c6d440522b1db1","kind":"tag","published_at":"2026-04-10T09:59:41.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_9_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_9_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_9_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_9_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_9_0/manifests"},{"name":"STRUTS_7_1_1","sha":"08a5eddc33c48a38fa3732fca0d216510c52dbab","kind":"tag","published_at":"2025-10-01T06:32:31.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_1_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_1_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_1_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_1_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_1_1/manifests"},{"name":"STRUTS_7_1_0","sha":"02858b7ed5c188507308441b3f0acc83c4658c12","kind":"tag","published_at":"2025-09-24T07:44:58.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_1_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_1_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_1_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_1_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_1_0/manifests"},{"name":"STRUTS_6_8_0","sha":"80225c7169436985c002ad258e6fd341c766829b","kind":"tag","published_at":"2025-09-15T05:46:23.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_8_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_8_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_8_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_8_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_8_0/manifests"},{"name":"STRUTS_6_7_4","sha":"8fb9aba74be6fda91a22858adff7d5eafe53bd7f","kind":"tag","published_at":"2025-02-20T12:20:52.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_7_4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_7_4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_7_4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_4/manifests"},{"name":"STRUTS_6_7_3","sha":"7909f43237d35c889d3b68ce223d80466d31ae0a","kind":"tag","published_at":"2025-02-17T10:34:15.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_7_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_7_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_7_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_3/manifests"},{"name":"STRUTS_7_0_3","sha":"4603706b40ae49de34f87c1a63f3ebd0efe48afc","kind":"tag","published_at":"2025-02-17T09:41:21.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_3/manifests"},{"name":"STRUTS_6_7_2","sha":"5038a9209fab97d9ab466ddecc17b6e143cf3a92","kind":"tag","published_at":"2025-02-04T06:39:40.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_7_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_7_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_7_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_2/manifests"},{"name":"STRUTS_7_0_2","sha":"932627976929bbcae7abccbdff8739741c48a0fb","kind":"tag","published_at":"2025-02-04T06:07:20.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_2/manifests"},{"name":"STRUTS_6_7_1","sha":"3227d5929ae0335b17d8e0d0845d4b5b560d4968","kind":"tag","published_at":"2025-02-02T09:16:26.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_7_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_7_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_7_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_1/manifests"},{"name":"STRUTS_7_0_1","sha":"f6bf43ae0b4387bdc7b956c416b4792f27d5fe42","kind":"tag","published_at":"2025-02-02T07:25:58.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_1/manifests"},{"name":"STRUTS_7_0_0","sha":"1d95543fbf2c873d5dab1773f951c38e3220b4e5","kind":"tag","published_at":"2024-12-11T06:56:25.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0/manifests"},{"name":"STRUTS_6_7_0","sha":"1f5305c249f20b27709dd2e60ec9459acf06fa07","kind":"tag","published_at":"2024-11-17T09:57:16.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_7_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_7_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_7_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_7_0/manifests"},{"name":"STRUTS_7_0_0_M10","sha":"5760d45a3efa5ec3c7a9d70678d1a4e02289d1c7","kind":"tag","published_at":"2024-11-03T13:50:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M10","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M10/manifests"},{"name":"STRUTS_6_6_1","sha":"c81245029267d2347c983a85f7ee33d53a2d5eb4","kind":"tag","published_at":"2024-10-05T14:08:33.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_6_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_6_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_6_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_6_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_6_1/manifests"},{"name":"STRUTS_7_0_0_M9","sha":"571c7eff0a8023386d66b4b64a8098090706793b","kind":"tag","published_at":"2024-07-21T06:59:39.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M9","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M9/manifests"},{"name":"STRUTS_6_6_0","sha":"d6e30b45daa61fc8849dc200e71750f54e75fb64","kind":"tag","published_at":"2024-07-20T06:28:41.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_6_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_6_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_6_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_6_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_6_0/manifests"},{"name":"STRUTS_6_5_0","sha":"dbfb59cb7cacbec9f81d2983113996d22424b149","kind":"tag","published_at":"2024-07-12T05:27:14.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_5_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_5_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_5_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_5_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_5_0/manifests"},{"name":"STRUTS_7_0_0_M8","sha":"4f8cb5211ff919271dc2c202ca8f2b93bd015f08","kind":"tag","published_at":"2024-07-11T07:48:20.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M8","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M8/manifests"},{"name":"STRUTS_7_0_0_M7","sha":"1057d4149b33238a9223962d93ca6a20aa938576","kind":"tag","published_at":"2024-06-12T05:45:18.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M7","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M7/manifests"},{"name":"STRUTS_7_0_0_M6","sha":"af53f0d93b8d0c4efa44e24347ebbddc6b69e8d1","kind":"tag","published_at":"2024-04-20T07:24:27.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M6","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M6/manifests"},{"name":"STRUTS_7_0_0_M5","sha":"4acb0d16da729e783bc4fdd763863f44116eb92c","kind":"tag","published_at":"2024-04-19T18:59:56.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M5","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M5/manifests"},{"name":"STRUTS_7_0_0_M4","sha":"aca2eb07ef9293575e1975d7810a85a825181a86","kind":"tag","published_at":"2024-04-19T06:38:24.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M4/manifests"},{"name":"STRUTS_6_4_0","sha":"9c5c80d1731a13af0dc80fc3a04700f9a15dcf2a","kind":"tag","published_at":"2024-04-07T09:22:11.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_4_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_4_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_4_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_4_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_4_0/manifests"},{"name":"STRUTS_7_0_0_M3","sha":"a35cfebf5abe89eabc50529c54826c519c0a747b","kind":"tag","published_at":"2024-02-24T08:22:37.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M3/manifests"},{"name":"STRUTS_7_0_0_M2","sha":"6db4c5150ed4ac6c8b2f67be7783794fa2060766","kind":"tag","published_at":"2024-02-01T09:39:54.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M2/manifests"},{"name":"STRUTS_7_0_0_M1","sha":"cd3389ab351ccb10c7ac9038f2d48e94a466a634","kind":"tag","published_at":"2024-01-20T10:39:04.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_7_0_0_M1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_7_0_0_M1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_7_0_0_M1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_7_0_0_M1/manifests"},{"name":"STRUTS_2_5_33","sha":"ca8d57c538136983a0180ac508ebcfabaf73f839","kind":"tag","published_at":"2023-12-05T06:42:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_33","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_33/manifests"},{"name":"STRUTS_6_3_0_2","sha":"ad95ab30f284e919d6560cbc396926f43bf8d32b","kind":"tag","published_at":"2023-12-05T06:04:08.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_3_0_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_3_0_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_3_0_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0_2/manifests"},{"name":"STRUTS_6_3_0_1","sha":"236ae15c661659b3b06d6381941f95700fcb7e00","kind":"tag","published_at":"2023-09-11T07:49:46.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_3_0_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_3_0_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_3_0_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0_1/manifests"},{"name":"STRUTS_6_1_2_2","sha":"6d8cf56977581b96633eff383c512ffccf1f0030","kind":"tag","published_at":"2023-09-11T06:47:13.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_1_2_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_1_2_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_1_2_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_2_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_2_2/manifests"},{"name":"STRUTS_2_5_32","sha":"bfb6c5431b198ec9fafd7f4e4593a3b1e0c3a853","kind":"tag","published_at":"2023-09-11T06:17:17.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_32","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_32/manifests"},{"name":"STRUTS_6_3_0","sha":"1a88f78a7ea2fba76b0b1a2a509f1b7084a34e98","kind":"tag","published_at":"2023-09-01T06:01:35.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_3_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_3_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_3_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0/manifests"},{"name":"STRUTS_6_3_0_RC1","sha":"3d72886b268e987241961c713111b3eca516808b","kind":"tag","published_at":"2023-07-16T07:48:07.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_3_0_RC1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_3_0_RC1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_3_0_RC1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0_RC1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_3_0_RC1/manifests"},{"name":"STRUTS_6_2_0","sha":"bb7cce26e99d6a7007b99cf40e90cb99ceea436a","kind":"tag","published_at":"2023-06-28T07:13:11.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_2_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_2_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_2_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_2_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_2_0/manifests"},{"name":"STRUTS_2_5_31","sha":"8274f77bc1648355c0292e7e50c489d233f9b212","kind":"tag","published_at":"2023-06-13T08:05:10.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_31","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_31/manifests"},{"name":"STRUTS_6_1_2_1","sha":"28498a807d4741f1438aedf6da6a26fe8d20a97a","kind":"tag","published_at":"2023-06-13T07:32:00.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_1_2_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_1_2_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_1_2_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_2_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_2_1/manifests"},{"name":"STRUTS_6_1_2","sha":"e903739624cc1e08d73bbe66c08d26794a71eb2f","kind":"tag","published_at":"2023-03-08T16:27:56.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_1_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_1_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_1_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_2/manifests"},{"name":"STRUTS_6_1_1","sha":"f5c0aa5f3ac7dce0c4e82092a8ff125c292f00f7","kind":"tag","published_at":"2022-11-15T14:30:09.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_1_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_1_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_1_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_1/manifests"},{"name":"STRUTS_6_1_0","sha":"18a72c3dff75a75b48e5fc44715b1ee3ec610a2a","kind":"tag","published_at":"2022-11-08T14:49:46.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_1_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_1_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_1_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_1_0/manifests"},{"name":"STRUTS_6_0_3","sha":"941d88d115ca21517cdfa09cb71512c818d0d471","kind":"tag","published_at":"2022-09-02T12:41:53.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_3/manifests"},{"name":"STRUTS_6_0_2","sha":"1380802b75adc662145fcf5c367bd73db3d3d1a0","kind":"tag","published_at":"2022-08-25T05:39:44.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_2/manifests"},{"name":"STRUTS_6_0_1","sha":"6536dc65d8a3b3e2effeb0b5f3b768bc77b8ced6","kind":"tag","published_at":"2022-08-12T15:26:52.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_1/manifests"},{"name":"STRUTS_6_0_0","sha":"68fb49c10e083dce829476778eec726fc90c8c38","kind":"tag","published_at":"2022-06-02T07:11:08.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0/manifests"},{"name":"STRUTS_6_0_0_RC4","sha":"981885fd6a8336ac36ca13e09f785cfa12d7770d","kind":"tag","published_at":"2022-05-24T11:59:27.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_0_RC4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_0_RC4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_0_RC4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC4/manifests"},{"name":"STRUTS_2_5_30","sha":"e4db6b720e4d3e798d0741dfe8c1ef2289fef8b7","kind":"tag","published_at":"2022-03-15T13:53:41.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_30","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_30/manifests"},{"name":"STRUTS_6_0_0_RC3","sha":"0c9f9c3400f1a91e01e06c4bfcd9ea12f9245ec5","kind":"tag","published_at":"2022-02-24T06:11:18.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_0_RC3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_0_RC3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_0_RC3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC3/manifests"},{"name":"STRUTS_6_0_0_RC2","sha":"f997d9b1ed876c8316c5b2b19760cdaf0b2bb6a6","kind":"tag","published_at":"2022-01-29T16:36:30.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_0_RC2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_0_RC2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_0_RC2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC2/manifests"},{"name":"STRUTS_2_5_29","sha":"00be9803d5ac4d6573179a460b4c0486d635f44a","kind":"tag","published_at":"2022-01-13T07:48:29.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_29","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_29/manifests"},{"name":"STRUTS_2_5_28_3","sha":"9f14276c00be34eb2148a0006ac5be3ce8131380","kind":"tag","published_at":"2021-12-30T06:34:51.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_28_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_28_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_28_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28_3/manifests"},{"name":"STRUTS_2_5_28_2","sha":"53aeafd7a2de6bd860e770874a677320ee6677bc","kind":"tag","published_at":"2021-12-22T06:43:14.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_28_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_28_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_28_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28_2/manifests"},{"name":"STRUTS_6_0_0_RC1","sha":"96aedf9bd5442a61897a19c96144e6fea48b83ce","kind":"tag","published_at":"2021-12-19T11:50:33.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_6_0_0_RC1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_6_0_0_RC1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_6_0_0_RC1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_6_0_0_RC1/manifests"},{"name":"STRUTS_2_5_28_1","sha":"8ce5811fe72fbdd9350966a42669c228ac1e84a5","kind":"tag","published_at":"2021-12-16T15:33:47.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_28_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_28_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_28_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28_1/manifests"},{"name":"STRUTS_2_5_28","sha":"dc579c0cccae85c4373ff5b10903488f0335fbc3","kind":"tag","published_at":"2021-11-29T07:33:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_28","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_28/manifests"},{"name":"STRUTS_2_5_27","sha":"26e1535b589c10a80b1d9f138d5b251931a512f7","kind":"tag","published_at":"2021-10-19T07:54:22.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_27","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_27/manifests"},{"name":"STRUTS_2_5_26","sha":"4cf9093cc527cafbd4c3423dfb24e088fb5b7b15","kind":"tag","published_at":"2020-11-25T16:32:02.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_26","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_26/manifests"},{"name":"STRUTS_2_5_25","sha":"b3a9d82d5830ef9cd7811cfa3f86a373ae52fada","kind":"tag","published_at":"2020-09-17T11:36:55.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_25","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_25/manifests"},{"name":"STRUTS_2_5_24","sha":"dcc59937a8cdf9d5369909f1cf9fb23d15f1baad","kind":"tag","published_at":"2020-08-18T05:38:32.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_24","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_24/manifests"},{"name":"STRUTS_2_5_23","sha":"e8656d57376842768e4d29a64195e85d0b5eab3a","kind":"tag","published_at":"2020-07-02T05:53:47.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_23","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_23/manifests"},{"name":"STRUTS_2_5_22","sha":"a6edb0d5df09e0d2cae0dd73ee974505cb363b82","kind":"tag","published_at":"2019-11-17T19:17:36.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_22","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_22/manifests"},{"name":"STRUTS_2_5_21","sha":"8dface4fcb7786108e9197a4f97f3e690f25f502","kind":"tag","published_at":"2019-11-07T19:17:58.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_21","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_21/manifests"},{"name":"STRUTS_2_5_20","sha":"96c38b27e432659bc1424b0f089dbf77ace961a2","kind":"tag","published_at":"2019-01-09T07:59:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_20","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_20/manifests"},{"name":"STRUTS_2_5_19","sha":"4456620b51542c40967df880cd93927cf5491e28","kind":"tag","published_at":"2018-12-30T14:24:09.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_19","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_19/manifests"},{"name":"STRUTS_2_3_37","sha":"60a1a2642ae7ddf74c0062fe37b3b57f83a0588e","kind":"tag","published_at":"2018-12-30T11:20:37.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_37","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_37/manifests"},{"name":"STRUTS_2_5_18","sha":"289782c5833944984d7b639a1028b72f94e0155b","kind":"tag","published_at":"2018-09-18T09:23:53.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_18","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_18/manifests"},{"name":"STRUTS_2_3_36","sha":"dd1588d3ebd7cb16db73006b53887c3638e69951","kind":"tag","published_at":"2018-09-18T07:55:11.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_36","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_36/manifests"},{"name":"STRUTS_2_5_17","sha":"eacc002334b42dc808099b12d2ce2a5177cab42d","kind":"tag","published_at":"2018-08-13T12:43:39.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_17","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_17/manifests"},{"name":"STRUTS_2_3_35","sha":"dbcca3512ee1a971cc0b44beac8f6b219a1bb153","kind":"tag","published_at":"2018-07-12T07:51:21.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_35","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_35/manifests"},{"name":"STRUTS_2_5_16","sha":"1fec084542c3bfe9c6733a947b3798210f73f8e8","kind":"tag","published_at":"2018-03-02T12:00:09.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_16","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_16/manifests"},{"name":"STRUTS_2_5_15","sha":"2c0facc3aa68339ad7bd23b52f3e54c0a3de90a5","kind":"tag","published_at":"2018-02-09T08:36:33.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_15","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_15/manifests"},{"name":"STRUTS_2_5_14_1","sha":"0856157e27cb402e9c339b938677c55d01f645eb","kind":"tag","published_at":"2017-11-29T07:35:53.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_14_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_14_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_14_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_14_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_14_1/manifests"},{"name":"STRUTS_2_5_14","sha":"04db84135866b136aa4366234e81a0e4aa7bc7ca","kind":"tag","published_at":"2017-11-14T06:43:30.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_14","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_14/manifests"},{"name":"STRUTS_2_3_34","sha":"f0b3a1d213d0018931c8ee85bbddb767f852f539","kind":"tag","published_at":"2017-09-05T18:37:30.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_34","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_34/manifests"},{"name":"STRUTS_2_5_13","sha":"9f5082615ede714618c8694c418210d43338daf6","kind":"tag","published_at":"2017-08-23T11:05:23.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_13","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_13/manifests"},{"name":"STRUTS_2_3_33","sha":"631ce98d171b1c7adb680b41a0303c61a81678fd","kind":"tag","published_at":"2017-07-07T12:47:20.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_33","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_33/manifests"},{"name":"STRUTS_2_5_12","sha":"ee74aea445883ff5ee235190722aa0fb04640a2e","kind":"tag","published_at":"2017-07-06T07:40:22.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_12","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_12/manifests"},{"name":"STRUTS_2_5_11","sha":"a249ed5f31a1aca8305c49500e6d21eed0c18b46","kind":"tag","published_at":"2017-06-22T11:11:24.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_11","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_11/manifests"},{"name":"STRUTS_2_3_32","sha":"1ed29d508fc0a3762ad7d16336a71adcf69bd88d","kind":"tag","published_at":"2017-03-06T11:03:13.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_32","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_32/manifests"},{"name":"STRUTS_2_5_10_1","sha":"376a891aeed6157d5621f9a9101d91be60f57b01","kind":"tag","published_at":"2017-03-06T10:26:52.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_10_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_10_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_10_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_10_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_10_1/manifests"},{"name":"STRUTS_2_5_10","sha":"f0f4e9ece77000e0eb0071bf233ed4b9bc9c8205","kind":"tag","published_at":"2017-01-27T09:35:24.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_10","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_10/manifests"},{"name":"STRUTS_2_5_9","sha":"ee27b6604a6e703ab5e802afa93ac43915d4373f","kind":"tag","published_at":"2017-01-17T09:27:18.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_9","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_9/manifests"},{"name":"STRUTS_2_5_8","sha":"4281e31864e0f2e0bffc0e537dc9c6e40604aec0","kind":"tag","published_at":"2016-12-06T10:18:02.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_8","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_8/manifests"},{"name":"STRUTS_2_5_7","sha":"5054ff469a416a1fd1331389e48aca6d22eef28f","kind":"tag","published_at":"2016-12-02T07:26:48.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_7","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_7/manifests"},{"name":"STRUTS_2_5_6","sha":"31a0768da35bb762db93e7931cadb8552f206a56","kind":"tag","published_at":"2016-11-28T20:15:50.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_6","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_6/manifests"},{"name":"STRUTS_2_5_5","sha":"f2348e53cbdf8ad7d9c28c66dc6fefe2c5718636","kind":"tag","published_at":"2016-10-11T18:40:45.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_5","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_5/manifests"},{"name":"STRUTS_2_5_4","sha":"12cc861875665e19c9d72a131f606a9b855b5c80","kind":"tag","published_at":"2016-10-06T19:04:10.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_4/manifests"},{"name":"STRUTS_2_3_31","sha":"de90290354a1c6c819687305e053232bc8a4a697","kind":"tag","published_at":"2016-10-05T06:53:29.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_31","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_31/manifests"},{"name":"STRUTS_2_5_3","sha":"c6a0ea2dcd6ea94bf551ed200955724013c34d3b","kind":"tag","published_at":"2016-10-05T05:44:50.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_3/manifests"},{"name":"STRUTS_2_5_2","sha":"17e14ef42bcf1182c2985f2a25543cf4e88235e2","kind":"tag","published_at":"2016-07-07T08:49:02.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_2/manifests"},{"name":"STRUTS_2_3_30","sha":"5c61c9a5752109a00ccdadbce3d4adb681f82c9a","kind":"tag","published_at":"2016-07-07T06:32:08.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_30","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_30/manifests"},{"name":"STRUTS_2_5_1","sha":"e8aa825f21fc951418f0cfa770d32762a4a83664","kind":"tag","published_at":"2016-06-14T06:07:40.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_1/manifests"},{"name":"STRUTS_2_3_29","sha":"bb22c585b5b52967fab033dba02cd244cd5b5b7a","kind":"tag","published_at":"2016-06-14T05:11:04.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_29","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_29/manifests"},{"name":"STRUTS_2_5","sha":"4bee55fee30086c786d09503125a2b1c2ae8dcfa","kind":"tag","published_at":"2016-05-05T13:21:44.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5/manifests"},{"name":"STRUTS_2_3_24_3","sha":"36b6fff05cd4a17f75b091c0edd52e0c1e65ec06","kind":"tag","published_at":"2016-04-20T12:03:26.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_24_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_24_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_24_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24_3/manifests"},{"name":"STRUTS_2_3_20_3","sha":"bbbf43ec59e7bef3b07e9065dc9784c18a95d58b","kind":"tag","published_at":"2016-04-20T10:47:55.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_20_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_20_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_20_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20_3/manifests"},{"name":"STRUTS_2_3_28_1","sha":"2cf0a7efeb12c8f476e31324dc56456b340ddeab","kind":"tag","published_at":"2016-04-19T12:44:35.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_28_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_28_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_28_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_28_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_28_1/manifests"},{"name":"STRUTS_2_3_24_2","sha":"a6e72347d2179a6d1a84acc0db54615c6f4b274c","kind":"tag","published_at":"2016-04-19T09:24:27.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_24_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_24_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_24_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24_2/manifests"},{"name":"STRUTS_2_3_20_2","sha":"d793648069386ce90fc9eae31e119de1a675f15a","kind":"tag","published_at":"2016-04-19T06:32:46.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_20_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_20_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_20_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20_2/manifests"},{"name":"STRUTS_2_3_28","sha":"0ac8932aa3a1b28a8f950863c17165cdc63b1474","kind":"tag","published_at":"2016-03-18T19:50:47.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_28","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_28/manifests"},{"name":"STRUTS_2_3_27","sha":"8a59ed02c958db9213f0e54d816882a902891761","kind":"tag","published_at":"2016-03-18T07:54:38.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_27","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_27/manifests"},{"name":"STRUTS_2_3_26","sha":"013077abcb8d450d7313fb9fc766fe45f0b6f9c5","kind":"tag","published_at":"2016-03-14T10:39:05.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_26","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_26/manifests"},{"name":"STRUTS_2_3_25","sha":"8ca0f2fc464f592fa95d8435d0924c3b9da981ef","kind":"tag","published_at":"2016-03-11T15:02:50.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_25","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_25/manifests"},{"name":"STRUTS_2_5_BETA3","sha":"9a63e6504b2d246573ff1483d45d9b12a49aa9c6","kind":"tag","published_at":"2016-01-21T08:26:12.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_BETA3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_BETA3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_BETA3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_BETA3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_BETA3/manifests"},{"name":"STRUTS_2_5_BETA2","sha":"56ae397d75430dc63fd68b0bfb36afbac1226023","kind":"tag","published_at":"2015-09-28T19:15:44.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_BETA2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_BETA2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_BETA2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_BETA2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_BETA2/manifests"},{"name":"STRUTS_2_3_24_1","sha":"7a9863169f7d981be0d2d57437974ae2cc0c8bd3","kind":"tag","published_at":"2015-09-22T05:49:33.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_24_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_24_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_24_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24_1/manifests"},{"name":"STRUTS_2_5_BETA1","sha":"2a37a2e32db6d6905de48e04f71d995f41055827","kind":"tag","published_at":"2015-07-17T07:36:24.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_5_BETA1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_5_BETA1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_5_BETA1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_BETA1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_5_BETA1/manifests"},{"name":"STRUTS_2_3_20_1","sha":"a9974eec5689a7113a6fb1e2096252f0935064dd","kind":"tag","published_at":"2015-05-06T05:59:06.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_20_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_20_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_20_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20_1/manifests"},{"name":"STRUTS_2_3_24","sha":"925741ad1e8e48c7a6d687fe02d3fdb6386eb64c","kind":"tag","published_at":"2015-05-03T10:08:03.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_24","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_24/manifests"},{"name":"STRUTS_2_3_23","sha":"d469fffed912764f7af2da861319815d088a66e8","kind":"tag","published_at":"2015-04-07T07:52:37.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_23","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_23/manifests"},{"name":"STRUTS_2_3_22","sha":"22573f8de8b33ead0fee88eb67817985464218bb","kind":"tag","published_at":"2015-03-19T06:11:22.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_22","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_22/manifests"},{"name":"STRUTS_2_3_21","sha":"a40e9a90bf8b5039728ff312852991e7d580bff4","kind":"tag","published_at":"2014-12-31T13:53:16.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_21","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_21/manifests"},{"name":"STRUTS_2_3_20","sha":"0320310406f6b11cfd235d7a9b866cf1de483a1e","kind":"tag","published_at":"2014-11-21T18:30:14.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_20","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_20/manifests"},{"name":"STRUTS_2_3_19","sha":"0032390ee89749c8dc55ac76f44900697aa0c713","kind":"tag","published_at":"2014-11-14T07:31:20.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_19","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_19/manifests"},{"name":"STRUTS_2_3_16_3","sha":"e03ff728618f5bf551083fc3a52d43c07434bbc9","kind":"tag","published_at":"2014-05-02T15:10:49.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_16_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_16_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_16_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16_3/manifests"},{"name":"STRUTS_2_3_16_2","sha":"7dd83dff485d324980f3d22c726cfd969ecf41f8","kind":"tag","published_at":"2014-04-24T19:32:43.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_16_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_16_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_16_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16_2/manifests"},{"name":"STRUTS_2_3_17","sha":"7908a88a405458869f61ecff4b775429724a3ea4","kind":"tag","published_at":"2014-04-06T12:01:59.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_17","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_17/manifests"},{"name":"STRUTS_2_3_16_1","sha":"6cddee6fc539429544b28a96361a8af7a0691108","kind":"tag","published_at":"2014-03-01T20:32:23.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_16_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_16_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_16_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16_1/manifests"},{"name":"STRUTS_2_3_16","sha":"402374de33146e1c0401a247e0779e290cb0c078","kind":"tag","published_at":"2013-11-30T10:27:46.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_16","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_16/manifests"},{"name":"STRUTS_2_3_15_3","sha":"3565f4d4f5c4c85a1ffab9e6169c86527aa6f4c7","kind":"tag","published_at":"2013-10-15T18:58:03.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_15_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_15_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_15_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15_3/manifests"},{"name":"STRUTS_2_3_15_2","sha":"fd206c1386cc113e3f5b52fbc5b2f15a458b31b4","kind":"tag","published_at":"2013-10-03T05:44:07.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_15_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_15_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_15_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15_2/manifests"},{"name":"STRUTS_2_3_15_1","sha":"8931ac19ea504a167f4d0c8e57ccc8f7f09f4135","kind":"tag","published_at":"2013-09-17T06:50:03.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_15_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_15_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_15_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15_1/manifests"},{"name":"STRUTS_2_3_15","sha":"bc6094eece7dfa65e7439cd018d58e85c5d41e47","kind":"tag","published_at":"2013-07-05T13:36:12.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_15","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_15/manifests"},{"name":"STRUTS_2_3_14_3","sha":"a72c1f4262a57bfe2819c6def81620d02d7867fb","kind":"tag","published_at":"2013-06-03T09:17:28.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_14_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_14_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_14_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14_3/manifests"},{"name":"STRUTS_2_3_14_2","sha":"f0c159d871ee741e0cc74fe858cc7be79841078c","kind":"tag","published_at":"2013-06-03T07:22:11.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_14_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_14_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_14_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14_2/manifests"},{"name":"STRUTS_2_3_14_1","sha":"fc3df96990bafdecc6f3a89cf7a4dcf15066c687","kind":"tag","published_at":"2013-04-18T18:05:47.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_14_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_14_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_14_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14_1/manifests"},{"name":"struts2-parent-2.3.14.1","sha":"b0ff4e70cde26746ef1f49b7e3eb96520e70ac9d","kind":"tag","published_at":"2013-04-18T13:31:58.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/struts2-parent-2.3.14.1","html_url":"https://github.com/apache/struts/releases/tag/struts2-parent-2.3.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@struts2-parent-2.3.14.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/struts2-parent-2.3.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/struts2-parent-2.3.14.1/manifests"},{"name":"STRUTS_2_3_14","sha":"9df00b0a864fac2e763b7c26ba99af057202f0f3","kind":"tag","published_at":"2013-03-28T20:51:33.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_14","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_14/manifests"},{"name":"STRUTS_2_3_13","sha":"6d3be1df385939526545714435f6c16fa3dc3d94","kind":"tag","published_at":"2013-03-24T09:58:04.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_13","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_13/manifests"},{"name":"STRUTS_2_3_12","sha":"f15f28a1766fe991de85c8cd089b102f77915319","kind":"tag","published_at":"2013-03-06T10:44:26.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_12","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_12/manifests"},{"name":"STRUTS_2_3_11","sha":"95814f0fa018ee284fb2c79710681a63dc5ee705","kind":"tag","published_at":"2013-02-28T06:34:01.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_11","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_11/manifests"},{"name":"STRUTS_2_3_10","sha":"f706c2fb2f48cba9bdb67e0ab806eb3cdeba25aa","kind":"tag","published_at":"2013-02-07T07:53:50.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_10","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_10/manifests"},{"name":"STRUTS_2_3_9","sha":"bef7211c41e7b0df9ff2740c0d4843f5b7a43266","kind":"tag","published_at":"2013-02-04T07:11:36.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_9","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_9/manifests"},{"name":"STRUTS_2_3_8","sha":"b2fe62824eebd213625d23378b5307dcb1b82c77","kind":"tag","published_at":"2012-12-16T11:45:13.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_8","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_8/manifests"},{"name":"STRUTS_2_3_7","sha":"28297863aee4d747638ce5b6f22262ac6a118ae0","kind":"tag","published_at":"2012-11-06T07:05:44.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_7","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_7/manifests"},{"name":"STRUTS_2_3_6","sha":"d0dddbc2065b4b157cc6eb9aff9588dab37b4791","kind":"tag","published_at":"2012-10-22T19:35:29.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_6","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_6/manifests"},{"name":"STRUTS_2_3_5","sha":"a41f1118fd838bfcac024e94711c8846fcfe87ef","kind":"tag","published_at":"2012-10-05T13:29:13.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_5","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_5/manifests"},{"name":"STRUTS_2_3_4_1","sha":"4b5f5619ddeda22f7f358431f604df580f1e61a1","kind":"tag","published_at":"2012-08-03T13:54:15.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_4_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_4_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_4_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_4_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_4_1/manifests"},{"name":"STRUTS_2_3_4","sha":"676a011b4f4d211e167465f3ffb03894c8f60334","kind":"tag","published_at":"2012-08-03T11:15:11.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_4/manifests"},{"name":"STRUTS_2_3_3","sha":"183be6b2986755eeac9b86eed9138304a30ff45e","kind":"tag","published_at":"2012-04-16T04:34:27.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_3/manifests"},{"name":"STRUTS_2_3_2","sha":"2fb25064f2b00c9d0e8ba11dc79cea662f00d8ec","kind":"tag","published_at":"2012-04-07T19:27:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_2/manifests"},{"name":"STRUTS_2_3_1_2","sha":"6246b8e12eb5abee95916b948a7a97e4d736f10b","kind":"tag","published_at":"2012-01-19T20:13:42.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_1_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_1_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_1_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_1_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_1_2/manifests"},{"name":"struts2-parent-2.3.1.2","sha":"733f686c0ea7ea0f136ff60058e516475ec8b6a3","kind":"tag","published_at":"2012-01-19T15:42:01.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/struts2-parent-2.3.1.2","html_url":"https://github.com/apache/struts/releases/tag/struts2-parent-2.3.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@struts2-parent-2.3.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/struts2-parent-2.3.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/struts2-parent-2.3.1.2/manifests"},{"name":"STRUTS_2_3_1_1","sha":"7d7d3fc42b013f0983a16473b10ed24efb988e0e","kind":"tag","published_at":"2011-12-24T22:32:10.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_1_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_1_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_1_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_1_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_1_1/manifests"},{"name":"STRUTS_2_3_1","sha":"e5009a34202777b53c5dc36e020d0033aa8be027","kind":"tag","published_at":"2011-12-08T21:07:36.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_3_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_3_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_3_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_3_1/manifests"},{"name":"STRUTS_2_2_3_1","sha":"2afda2ecc45730f5c0fc1f88c5d8919fb34d1462","kind":"tag","published_at":"2011-09-07T10:47:31.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_2_3_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_2_3_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_2_3_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_3_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_3_1/manifests"},{"name":"STRUTS_2_2_3","sha":"c80cb8458966e10d88a192b5ce68e47aee0e944a","kind":"tag","published_at":"2011-05-07T09:45:45.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_2_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_2_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_2_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_3/manifests"},{"name":"STRUTS_2_2_2","sha":"d3ae3f2badc9ed85467d5ffc64e07c4b08805fe1","kind":"tag","published_at":"2011-03-26T12:06:00.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_2_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_2_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_2_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_2/manifests"},{"name":"STRUTS_2_2_1_1","sha":"f9d681cc97a175676786ddebed6b5924187e5ae3","kind":"tag","published_at":"2010-12-14T06:58:58.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_2_1_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_2_1_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_2_1_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_1_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_1_1/manifests"},{"name":"STRUTS_2_2_1","sha":"2bbc0452601e9816eabcffae0775f9549a651e4c","kind":"tag","published_at":"2010-11-22T20:01:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_2_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_2_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_2_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_1/manifests"},{"name":"STRUTS_2_2_0","sha":"afc9238f5a5cb1e6dfab9ddfbae4ba9f4a3ae3cf","kind":"tag","published_at":"2010-06-29T04:54:59.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_2_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_2_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_2_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_2_0/manifests"},{"name":"STRUTS_2_1_8_1","sha":"ef3c3ece89c6723340c9bc9271e3d2130378afad","kind":"tag","published_at":"2009-10-02T19:46:07.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_8_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_8_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_8_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_8_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_8_1/manifests"},{"name":"STRUTS_2_1_8","sha":"3f3776e7dcf106fe05041c743ea32c779e595197","kind":"tag","published_at":"2009-09-23T00:38:47.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_8","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_8/manifests"},{"name":"STRUTS_2_1_7","sha":"8e5327eaaeb07711b2ffd29e6b6bd9169ac6d8bf","kind":"tag","published_at":"2009-06-18T18:08:29.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_7","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_7/manifests"},{"name":"STRUTS_2_1_6","sha":"e893492adcacc5b4f09f378fe1d8f80de1814038","kind":"tag","published_at":"2009-01-05T19:57:18.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_6","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_6/manifests"},{"name":"STRUTS_2_1_5","sha":"28c17a1b779635a3f3af39169224ea335a0379e2","kind":"tag","published_at":"2009-01-02T16:28:13.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_5","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_5/manifests"},{"name":"STRUTS_2_1_4","sha":"6bf54d0b555cf64d46243054a1a8f57356b38f2b","kind":"tag","published_at":"2008-12-29T18:56:40.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_4/manifests"},{"name":"STRUTS_2_1_3","sha":"daa62ed42adee485f30f2e8f43893900b5cd64e9","kind":"tag","published_at":"2008-12-25T06:41:44.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_3/manifests"},{"name":"STRUTS_2_0_14","sha":"6fa6f1014b309a96755e94d13563052055402701","kind":"tag","published_at":"2008-11-16T23:58:17.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_14","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_14/manifests"},{"name":"STRUTS_2_0_X","sha":"10479d7f6e33761f4178defdcfc5e4af0279051b","kind":"tag","published_at":"2008-11-16T23:55:15.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_X","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_X","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_X","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_X","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_X/manifests"},{"name":"STRUTS_2_0_13","sha":"f187d90a12dd4b5c22a11d7ce7b6549f29516ff8","kind":"tag","published_at":"2008-10-27T22:40:57.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_13","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_13/manifests"},{"name":"STRUTS_2_0_12","sha":"645d06e11668b66204db10b5628685650333c5c1","kind":"tag","published_at":"2008-10-16T00:41:59.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_12","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_12/manifests"},{"name":"STRUTS_2_0_11_2","sha":"77cd231b589249b07f36e29061970070ecdd50f3","kind":"tag","published_at":"2008-06-22T17:10:35.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_11_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_11_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_11_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_11_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_11_2/manifests"},{"name":"STRUTS_2_1_2","sha":"f633bb8270ea52b8d168ade14b8721d8739ceab1","kind":"tag","published_at":"2008-05-02T04:51:02.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_2/manifests"},{"name":"STRUTS_2_1_1","sha":"6a39976815adf55ada5c4e246d57ec13d9a5ec99","kind":"tag","published_at":"2008-04-17T13:24:25.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_1/manifests"},{"name":"STRUTS_2_0_11_1","sha":"4b744ef87b9bd8ebff43675259df3ae650c9585e","kind":"tag","published_at":"2008-03-02T14:31:04.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_11_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_11_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_11_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_11_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_11_1/manifests"},{"name":"STRUTS_2_1_0","sha":"ea055ccb9d7dde6a55a0173e1ecff023fb402334","kind":"tag","published_at":"2007-10-29T01:12:30.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_1_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_1_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_1_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_1_0/manifests"},{"name":"STRUTS_2_0_11","sha":"e372ca3d17ba24778cf57e502ba85bc75b613f2c","kind":"tag","published_at":"2007-09-22T00:01:43.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_11","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_11/manifests"},{"name":"STRUTS_2_0_10","sha":"b8cadf565addce57581d13e9a8011eec6f42b0f4","kind":"tag","published_at":"2007-09-12T23:36:53.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_10","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_10/manifests"},{"name":"struts2-parent-2.0.10","sha":"2ac88b92f161a7b7411881e460a5f80dbe0db61a","kind":"tag","published_at":"2007-09-10T23:56:07.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/struts2-parent-2.0.10","html_url":"https://github.com/apache/struts/releases/tag/struts2-parent-2.0.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@struts2-parent-2.0.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/struts2-parent-2.0.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/struts2-parent-2.0.10/manifests"},{"name":"STRUTS_2_0_9","sha":"b3f712eb1b6b7d38b6f3dce6ee63147f0f96c259","kind":"tag","published_at":"2007-07-23T17:24:17.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_9","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_9/manifests"},{"name":"STRUTS_2_0_8","sha":"8135547c7a53364c17a93ba0a38f0463f0315ac5","kind":"tag","published_at":"2007-06-06T16:07:32.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_8","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_8/manifests"},{"name":"STRUTS_2_0_7","sha":"de154978ca69a59079024dc6468eedd261293bff","kind":"tag","published_at":"2007-03-20T14:01:59.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_7","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_7/manifests"},{"name":"STRUTS_2_0_6","sha":"fe62eb03471666cb871c1d5969b98dc79d578d2d","kind":"tag","published_at":"2007-02-19T01:56:17.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_6","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_6/manifests"},{"name":"STRUTS_2_0_5","sha":"cb580fe614d5ff73776c34e39a93aae2ad557757","kind":"tag","published_at":"2007-02-05T15:33:40.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_5","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_5/manifests"},{"name":"STRUTS_2_0_4","sha":"df365f17ea11e319302f648e86da3188ce1c5656","kind":"tag","published_at":"2007-01-29T03:40:41.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_4","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_4/manifests"},{"name":"STRUTS_2_0_3","sha":"a614104a485c8b1a8d16d51511b50d922f00ab3f","kind":"tag","published_at":"2007-01-20T03:43:59.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_3","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_3/manifests"},{"name":"STRUTS_2_0_2","sha":"591347a498b358112cf478a3135107eae39d6e43","kind":"tag","published_at":"2006-12-31T16:12:20.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_2","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_2/manifests"},{"name":"STRUTS_2_0_1","sha":"2a4ea6dce4e2d622a57480c1bc337f46315fde96","kind":"tag","published_at":"2006-10-10T22:03:04.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_1","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_1/manifests"},{"name":"STRUTS_2_0_0","sha":"2c0a197cea8fdc7d8cda5eeaa15a1c76507ac0a5","kind":"tag","published_at":"2006-09-24T17:18:08.000Z","download_url":"https://codeload.github.com/apache/struts/tar.gz/STRUTS_2_0_0","html_url":"https://github.com/apache/struts/releases/tag/STRUTS_2_0_0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/apache/struts@STRUTS_2_0_0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/tags/STRUTS_2_0_0/manifests"}]},"repo_metadata_updated_at":"2026-09-21T17:33:39.794Z","dependent_packages_count":194,"downloads":null,"downloads_period":null,"dependent_repos_count":6183,"rankings":{"downloads":null,"dependent_repos_count":0.11481125270497716,"dependent_packages_count":0.39412519035024446,"stargazers_count":10.738358579786809,"forks_count":6.263324517111485,"docker_downloads_count":0.5383906387753467,"average":3.6098020357457727},"purl":"pkg:maven/org.apache.struts/struts2-core","advisories":[{"uuid":"GSA_kwCzR0hTQS1xY2ZjLWhtcmMtNTl4N84ABQ7K","url":"https://github.com/advisories/GHSA-qcfc-hmrc-59x7","title":"Apache Struts 2 is Missing XML Validation","description":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-01-11T15:31:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-68493","https://cwiki.apache.org/confluence/display/WW/S2-069","http://www.openwall.com/lists/oss-security/2026/01/11/2","https://github.com/advisories/GHSA-qcfc-hmrc-59x7"],"source_kind":"github","identifiers":["GHSA-qcfc-hmrc-59x7","CVE-2025-68493"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-13T22:00:08.032Z","updated_at":"2026-09-25T12:06:21.563Z","epss_percentage":0.45847,"epss_percentile":0.98762,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xY2ZjLWhtcmMtNTl4N84ABQ7K","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xY2ZjLWhtcmMtNTl4N84ABQ7K","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.2.1, \u003c 6.1.1"}],"purl":null},{"ecosystem":"maven","package_name":"com.opensymphony:xwork","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.2.1"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"6.1.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.1.1"},{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.5.0, \u003c= 2.5.33"},{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.3.37"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xY2ZjLWhtcmMtNTl4N84ABQ7K/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yZzU4LXhoaDctbXFqd84ABPf2","url":"https://github.com/advisories/GHSA-rg58-xhh7-mqjw","title":"Apache Struts has a Denial of Service vulnerability","description":"Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.\n\nThis issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.\n\nUsers are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-12-10T12:31:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-66675","https://cve.org/CVERecord?id=CVE-2025-64775","https://cwiki.apache.org/confluence/display/WW/S2-068","https://github.com/apache/struts/commit/831568929cfba700f790f6ebe6e335f9f33fb468","https://github.com/advisories/GHSA-rg58-xhh7-mqjw"],"source_kind":"github","identifiers":["GHSA-rg58-xhh7-mqjw","CVE-2025-66675"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-12-10T18:00:08.282Z","updated_at":"2026-09-25T12:06:40.386Z","epss_percentage":0.00594,"epss_percentile":0.46065,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yZzU4LXhoaDctbXFqd84ABPf2","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yZzU4LXhoaDctbXFqd84ABPf2","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"7.1.1","vulnerable_version_range":"\u003e= 7.0.0, \u003c 7.1.1"},{"first_patched_version":"6.8.0","vulnerable_version_range":"\u003e= 2.0.0, \u003c 6.8.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yZzU4LXhoaDctbXFqd84ABPf2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14eDd2LWhxeGgtY2pyOc4ABPEO","url":"https://github.com/advisories/GHSA-xx7v-hqxh-cjr9","title":"Apache Struts is Vulnerable to DoS via File Leak","description":"Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.\n\nThis issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3.\n\nUsers are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-12-01T18:30:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-64775","https://cwiki.apache.org/confluence/display/WW/S2-068","http://www.openwall.com/lists/oss-security/2025/12/01/2","https://github.com/advisories/GHSA-xx7v-hqxh-cjr9"],"source_kind":"github","identifiers":["GHSA-xx7v-hqxh-cjr9","CVE-2025-64775"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-12-03T14:00:08.610Z","updated_at":"2026-09-25T18:05:08.478Z","epss_percentage":0.0152,"epss_percentile":0.72905,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14eDd2LWhxeGgtY2pyOc4ABPEO","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14eDd2LWhxeGgtY2pyOc4ABPEO","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.5.0, \u003c= 2.5.33"},{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.3.37"},{"first_patched_version":"7.1.1","vulnerable_version_range":"\u003e= 7.0.0, \u003c 7.1.1"},{"first_patched_version":"6.8.0","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.8.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14eDd2LWhxeGgtY2pyOc4ABPEO/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00M21xLTZ4bWctMjl2bc4ABCSU","url":"https://github.com/advisories/GHSA-43mq-6xmg-29vm","title":"Apache Struts file upload logic is flawed","description":"File upload logic is flawed vulnerability in Apache Struts. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.\n\nThis issue affects Apache Struts: from 2.0.0 before 6.4.0.\n\nUsers are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload. If you are not using an old file upload logic based on FileuploadInterceptor your application is safe.\n\nYou can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067 .","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-12-11T18:30:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.5,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:A/V:C/RE:L/U:Red","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-53677","https://cwiki.apache.org/confluence/display/WW/S2-067","https://struts.apache.org/core-developers/file-upload","https://security.netapp.com/advisory/ntap-20250103-0005","https://github.com/apache/struts/commit/1ecfbae46543a83e131404f8dcc84b3d0d554854","https://github.com/apache/struts/commit/3ef9ade8902a63bb560892453eeca02bfddefc78","https://github.com/apache/struts/commit/930fef7679d7247db9e460c146b1698a9d7ad1e4","https://www.dynatrace.com/news/blog/the-anatomy-of-broken-apache-struts-2-a-technical-deep-dive-into-cve-2024-53677","https://github.com/advisories/GHSA-43mq-6xmg-29vm"],"source_kind":"github","identifiers":["GHSA-43mq-6xmg-29vm","CVE-2024-53677"],"repository_url":"https://github.com/apache/struts","blast_radius":36.01639284173932,"created_at":"2024-12-11T23:07:34.647Z","updated_at":"2026-09-22T08:08:52.239Z","epss_percentage":0.70143,"epss_percentile":0.99346,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00M21xLTZ4bWctMjl2bc4ABCSU","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00M21xLTZ4bWctMjl2bc4ABCSU","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"6.4.0","vulnerable_version_range":"\u003c 6.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00M21xLTZ4bWctMjl2bc4ABCSU/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yajM5LXFjam0tNDI4d84AA3mt","url":"https://github.com/advisories/GHSA-2j39-qcjm-428w","title":"Apache Struts vulnerable to path traversal","description":"An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.\nUsers are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2023-12-07T09:30:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-50164","https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj","http://www.openwall.com/lists/oss-security/2023/12/07/1","https://github.com/apache/struts/commit/162e29fee9136f4bfd9b2376da2cbf590f9ea163","https://github.com/apache/struts/commit/d8c69691ef1d15e76a5f4fcf33039316da2340b6","https://www.openwall.com/lists/oss-security/2023/12/07/1","http://packetstormsecurity.com/files/176157/Struts-S2-066-File-Upload-Remote-Code-Execution.html","https://cwiki.apache.org/confluence/display/WW/S2-066","https://security.netapp.com/advisory/ntap-20231214-0010","https://github.com/advisories/GHSA-2j39-qcjm-428w"],"source_kind":"github","identifiers":["GHSA-2j39-qcjm-428w","CVE-2023-50164"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-12-07T22:07:58.598Z","updated_at":"2026-09-25T19:10:38.938Z","epss_percentage":0.80819,"epss_percentile":0.99578,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yajM5LXFjam0tNDI4d84AA3mt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yajM5LXFjam0tNDI4d84AA3mt","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"6.3.0.2","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.3.0.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yajM5LXFjam0tNDI4d84AA3mt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03MjlxLWZjZ3AtcjV4aM4AA3kR","url":"https://github.com/advisories/GHSA-729q-fcgp-r5xh","title":"Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability","description":"When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied.\nUsers are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fix this issue.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-12-05T09:33:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-41835","https://lists.apache.org/thread/6wj530kh3ono8phr642y9sqkl67ys2ft","https://github.com/apache/struts/commit/3292152f8c0a77ee4827beede82b6580478a2c2a","https://github.com/apache/struts/commit/4c044f12560e22e00520595412830f9582d6dac7","https://github.com/apache/struts/commit/bf54436869c264941dd192c752a4abfaa65d3711","http://www.openwall.com/lists/oss-security/2023/12/09/1","https://www.openwall.com/lists/oss-security/2023/12/09/1","https://security.netapp.com/advisory/ntap-20231013-0001","https://github.com/advisories/GHSA-729q-fcgp-r5xh"],"source_kind":"github","identifiers":["GHSA-729q-fcgp-r5xh","CVE-2023-41835"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-12-06T00:05:57.443Z","updated_at":"2026-09-24T15:11:42.094Z","epss_percentage":0.073,"epss_percentile":0.94178,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03MjlxLWZjZ3AtcjV4aM4AA3kR","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03MjlxLWZjZ3AtcjV4aM4AA3kR","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.32","vulnerable_version_range":"\u003c 2.5.32"},{"first_patched_version":"6.1.2.2","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.1.2.2"},{"first_patched_version":"6.3.0.1","vulnerable_version_range":"\u003e= 6.2.0, \u003c 6.3.0.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03MjlxLWZjZ3AtcjV4aM4AA3kR/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00ZzQyLWdxcmctNDYzM84AAz2O","url":"https://github.com/advisories/GHSA-4g42-gqrg-4633","title":"Apache Struts vulnerable to memory exhaustion","description":"Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-06-14T09:30:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-34396","https://cwiki.apache.org/confluence/display/WW/S2-064","https://github.com/apache/struts/commit/2d6f1bc0a6f5ac575a56784ac6461816b67c4f21","https://github.com/apache/struts/releases/tag/STRUTS_2_5_31","https://github.com/apache/struts/releases/tag/STRUTS_6_1_2_1","http://www.openwall.com/lists/oss-security/2023/06/14/3","https://security.netapp.com/advisory/ntap-20230706-0005","https://github.com/advisories/GHSA-4g42-gqrg-4633"],"source_kind":"github","identifiers":["GHSA-4g42-gqrg-4633","CVE-2023-34396"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-06-14T21:03:30.138Z","updated_at":"2026-09-25T19:12:29.379Z","epss_percentage":0.05512,"epss_percentile":0.925,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ZzQyLWdxcmctNDYzM84AAz2O","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00ZzQyLWdxcmctNDYzM84AAz2O","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"6.1.2.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.1.2.1"},{"first_patched_version":"2.5.31","vulnerable_version_range":"\u003c 2.5.31"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ZzQyLWdxcmctNDYzM84AAz2O/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04ZjZ4LXY2ODUtZzJ4Y84AAz2D","url":"https://github.com/advisories/GHSA-8f6x-v685-g2xc","title":"Apache Struts vulnerable to memory exhaustion","description":"Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-06-14T09:30:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-34149","https://cwiki.apache.org/confluence/display/WW/S2-063","https://github.com/apache/struts/commit/2d6f1bc0a6f5ac575a56784ac6461816b67c4f21","https://github.com/apache/struts/releases/tag/STRUTS_2_5_31","https://github.com/apache/struts/releases/tag/STRUTS_6_1_2_1","http://www.openwall.com/lists/oss-security/2023/06/14/2","https://security.netapp.com/advisory/ntap-20230706-0005","https://github.com/advisories/GHSA-8f6x-v685-g2xc"],"source_kind":"github","identifiers":["GHSA-8f6x-v685-g2xc","CVE-2023-34149"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-06-14T21:03:30.151Z","updated_at":"2026-08-21T12:10:41.659Z","epss_percentage":0.05448,"epss_percentile":0.92106,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ZjZ4LXY2ODUtZzJ4Y84AAz2D","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04ZjZ4LXY2ODUtZzJ4Y84AAz2D","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"6.1.2.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.1.2.1"},{"first_patched_version":"2.5.31","vulnerable_version_range":"\u003c 2.5.31"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ZjZ4LXY2ODUtZzJ4Y84AAz2D/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jY3A1LWdnNTgtcHhmbc4AAl6h","url":"https://github.com/advisories/GHSA-ccp5-gg58-pxfm","title":"Improper Preservation of Permissions in Apache Struts","description":"An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-24T17:28:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2019-0233","https://cwiki.apache.org/confluence/display/ww/s2-060","https://launchpad.support.sap.com/#/notes/2982840","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/advisories/GHSA-ccp5-gg58-pxfm"],"source_kind":"github","identifiers":["GHSA-ccp5-gg58-pxfm","CVE-2019-0233"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:12:16.218Z","updated_at":"2026-08-21T12:12:00.280Z","epss_percentage":0.6805,"epss_percentile":0.99268,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jY3A1LWdnNTgtcHhmbc4AAl6h","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jY3A1LWdnNTgtcHhmbc4AAl6h","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.22","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.5.22"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jY3A1LWdnNTgtcHhmbc4AAl6h/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yNjVyLXBwODMtZ3d3N84AAjsD","url":"https://github.com/advisories/GHSA-265r-pp83-gww7","title":"Cross-site Scripting in Apache Struts","description":"When the Struts2 debug mode is turned on, under certain conditions an arbitrary script may be executed in the 'Problem Report' screen. Also if JSP files are exposed to be accessed directly it's possible to execute an arbitrary script. \n\nIt is generally not advisable to have debug mode switched on outside of the development environment. Debug mode should always be turned off in production setup. Also never expose JSPs files directly and hide them inside WEB-INF folder or define dedicated security constraints to block access to raw JSP files.\n\nStruts \u003e= 2.3.20 is not vulnerable to this attack. We recommend upgrading to Struts 2.3.20 or higher if turning off debug mode is not possible.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-24T17:09:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2015-2992","https://security.netapp.com/advisory/ntap-20200330-0001/","http://jvn.jp/en/jp/JVN88408929/index.html","http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000124.html","http://www.securityfocus.com/bid/76624","https://cwiki.apache.org/confluence/display/WW/S2-025","https://cwiki.apache.org/confluence/display/WW/Security","https://github.com/advisories/GHSA-265r-pp83-gww7"],"source_kind":"github","identifiers":["GHSA-265r-pp83-gww7","CVE-2015-2992"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.836Z","updated_at":"2026-08-28T18:11:37.053Z","epss_percentage":0.05757,"epss_percentile":0.92509,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNjVyLXBwODMtZ3d3N84AAjsD","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yNjVyLXBwODMtZ3d3N84AAjsD","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20","vulnerable_version_range":"\u003c 2.3.20"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNjVyLXBwODMtZ3d3N84AAjsD/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qZ2NyLTljMnEtcnZwOM4AAgP6","url":"https://github.com/advisories/GHSA-jgcr-9c2q-rvp8","title":"Apache Struts is vulnerable to Cross-site Scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) \" (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T05:52:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2008-6682","https://issues.apache.org/struts/browse/WW-2414","https://issues.apache.org/struts/browse/WW-2427","https://github.com/apache/struts/commit/09147ffad2b3046ed21af0f524c5088e2ac551e6","https://github.com/apache/struts/commit/bd3f2f59c9b09f70aed3ebab6bb69b464ee2d6cb","https://github.com/apache/struts/commit/dae026a0f0511f83852053bae9d5a622e7f80486","https://web.archive.org/web/20080610075918/http://www.nabble.com/Feedback%3A-WW-2414%2C-XSS-attack-is-possible-if-using-%3Cs%3Aurl-...%3E-and-%3Cs%3Aa-...%3E-td14771449i20.html","https://web.archive.org/web/20080611112834/http://www.nabble.com/Feedback%3A-WW-2414%2C-XSS-attack-is-possible-if-using-%3Cs%3Aurl-...%3E-and-%3Cs%3Aa-...%3E-td14771449.html","https://web.archive.org/web/20200229155553/http://www.securityfocus.com/bid/34686","https://github.com/advisories/GHSA-jgcr-9c2q-rvp8"],"source_kind":"github","identifiers":["GHSA-jgcr-9c2q-rvp8","CVE-2008-6682"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2024-02-09T20:05:11.215Z","updated_at":"2026-09-22T08:11:50.016Z","epss_percentage":0.05614,"epss_percentile":0.92509,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZ2NyLTljMnEtcnZwOM4AAgP6","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qZ2NyLTljMnEtcnZwOM4AAgP6","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.1.1","vulnerable_version_range":"\u003e= 2.1.0, \u003c 2.1.1"},{"first_patched_version":"2.0.11.1","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.0.11.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZ2NyLTljMnEtcnZwOM4AAgP6/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13djdnLXhodnctOGhjcM4AAgPc","url":"https://github.com/advisories/GHSA-wv7g-xhvw-8hcp","title":"Apache Struts directory traversal vulnerability","description":"Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a `..%252f` (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T05:52:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2008-6505","http://issues.apache.org/struts/browse/WW-2779","http://struts.apache.org/2.x/docs/s2-004.html","https://github.com/apache/struts/commit/04fcefa44bae1263c7cad6986a9dafed67f0164f","https://github.com/apache/struts/commit/1f1c996eb1f0f3e2193fba0075f62ccd04e3c0c3","https://web.archive.org/web/20081208214512/http://secunia.com/advisories/32497","https://web.archive.org/web/20111025094319/http://www.securityfocus.com/bid/32104","https://github.com/advisories/GHSA-wv7g-xhvw-8hcp"],"source_kind":"github","identifiers":["GHSA-wv7g-xhvw-8hcp","CVE-2008-6505"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2024-02-09T20:05:11.265Z","updated_at":"2026-09-15T18:09:39.948Z","epss_percentage":0.72711,"epss_percentile":0.99401,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13djdnLXhodnctOGhjcM4AAgPc","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13djdnLXhodnctOGhjcM4AAgPc","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.1.3","vulnerable_version_range":"\u003e= 2.1.0, \u003c 2.1.3"},{"first_patched_version":"2.0.12","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.0.12"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13djdnLXhodnctOGhjcM4AAgPc/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01NmY4LWc2OHItajY5Oc4AAf1H","url":"https://github.com/advisories/GHSA-56f8-g68r-j699","title":"Cross-site Scripting in Apache Struts","description":"Multiple Cross-Site Scripting (XSS) in XWork generated error pages in Apache Struts. By default, XWork doesn't escape action's names in automatically generated error page, allowing for a successful XSS attack. When Dynamic Method Invocation (DMI) is enabled, the action name is generated dynamically base on request parameters. This allows to call non-existing page and method to produce error page with injected code as below. As of Struts 2.2.3 the action names are escaped when automatically generated error pages are rendered.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2022-05-17T05:35:28.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2011-1772","https://issues.apache.org/jira/browse/WW-3579","http://jvn.jp/en/jp/JVN25435092/index.html","http://jvndb.jvn.jp/jvndb/JVNDB-2011-000106","http://secureappdev.blogspot.com/2011/05/apache-struts-2-xwork-webwork-reflected.html","http://struts.apache.org/2.2.3/docs/version-notes-223.html","http://struts.apache.org/2.x/docs/s2-006.html","https://github.com/advisories/GHSA-56f8-g68r-j699"],"source_kind":"github","identifiers":["GHSA-56f8-g68r-j699","CVE-2011-1772"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.876Z","updated_at":"2026-08-21T12:11:29.272Z","epss_percentage":0.33346,"epss_percentile":0.9824,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NmY4LWc2OHItajY5Oc4AAf1H","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01NmY4LWc2OHItajY5Oc4AAf1H","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.2.3","vulnerable_version_range":"\u003c 2.2.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NmY4LWc2OHItajY5Oc4AAf1H/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zZzhqLWpqNTQtM3ZqZ84AAe4O","url":"https://github.com/advisories/GHSA-3g8j-jj54-3vjg","title":"Apache Struts is vulnerable to Cross-site Scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in `config-browser/`.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T04:57:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-6348","http://packetstormsecurity.com/files/123805/Struts-2.3.15.3-Cross-Site-Scripting.html","http://seclists.org/fulldisclosure/2013/Oct/244","https://issues.apache.org/jira/browse/WW-4213","https://security-tracker.debian.org/tracker/CVE-2013-6348","https://svn.apache.org/viewvc?view=revision\u0026revision=1533354","https://ubuntu.com/security/CVE-2013-6348","https://github.com/advisories/GHSA-3g8j-jj54-3vjg"],"source_kind":"github","identifiers":["GHSA-3g8j-jj54-3vjg","CVE-2013-6348"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:53.150Z","updated_at":"2026-08-15T20:17:22.059Z","epss_percentage":0.06125,"epss_percentile":0.92524,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZzhqLWpqNTQtM3ZqZ84AAe4O","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zZzhqLWpqNTQtM3ZqZ84AAe4O","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.16","vulnerable_version_range":"\u003c 2.3.16"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZzhqLWpqNTQtM3ZqZ84AAe4O/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xNXE4LWpnaGYtM3BtM84AAekz","url":"https://github.com/advisories/GHSA-q5q8-jghf-3pm3","title":"Apache Struts2 Broken Access Control Vulnerability","description":"The Struts 2 action mapping mechanism supports the special parameter prefix action: which is intended to help with attaching navigational information to buttons within forms, under certain conditions this can be used to bypass security constraints. \n\nIn Struts 2.3.15.3 the action mapping mechanism was changed to avoid circumventing security constraints. Two additional constants were introduced to steer behaviour of DefaultActionMapper:\n\n- struts.mapper.action.prefix.enabled - when set to false support for \"action:\" prefix is disabled, set to false by default\n- struts.mapper.action.prefix.crossNamespaces - when set to false, actions defined with \"action:\" prefix must be in the same namespace as current action\n\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T04:44:52.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-4310","http://struts.apache.org/release/2.3.x/docs/s2-018.html","https://github.com/apache/struts/commit/0c8366cb792227d484b9ca13e537037dd0cb57dc","https://github.com/advisories/GHSA-q5q8-jghf-3pm3"],"source_kind":"github","identifiers":["GHSA-q5q8-jghf-3pm3","CVE-2013-4310"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:52.902Z","updated_at":"2026-09-25T19:12:10.476Z","epss_percentage":0.06523,"epss_percentile":0.93527,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNXE4LWpnaGYtM3BtM84AAekz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xNXE4LWpnaGYtM3BtM84AAekz","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.15.3","vulnerable_version_range":"\u003c 2.3.15.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNXE4LWpnaGYtM3BtM84AAekz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yajRxLTlmZmYtMjM2as4AAdCC","url":"https://github.com/advisories/GHSA-2j4q-9fff-236j","title":"Apache Struts XSS Vulnerability","description":"Apache Struts 2.x before 2.3.28 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T03:42:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-2162","http://struts.apache.org/docs/s2-030.html","https://web.archive.org/web/20210123095722/http://www.securityfocus.com/bid/85070","https://web.archive.org/web/20210801130539/http://www.securitytracker.com/id/1035272","https://github.com/apache/struts/blob/f511034acd7b97e07d281169b38e2af40c94903d/core/src/main/java/org/apache/struts2/interceptor/I18nInterceptor.java","https://github.com/apache/struts/commit/fc2179cf1ac9fbfb61e3430fa88b641d87253327","https://github.com/advisories/GHSA-2j4q-9fff-236j"],"source_kind":"github","identifiers":["GHSA-2j4q-9fff-236j","CVE-2016-2162"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-07-31T23:03:46.313Z","updated_at":"2026-09-24T15:11:53.827Z","epss_percentage":0.0778,"epss_percentile":0.9438,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yajRxLTlmZmYtMjM2as4AAdCC","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yajRxLTlmZmYtMjM2as4AAdCC","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.28","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.28"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yajRxLTlmZmYtMjM2as4AAdCC/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zODNwLXhxeHgtcnJtcM4AAdBJ","url":"https://github.com/advisories/GHSA-383p-xqxx-rrmp","title":"Denial of service in Apache Struts","description":"Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T03:42:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-3093","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E","https://struts.apache.org/docs/s2-034.html","https://github.com/advisories/GHSA-383p-xqxx-rrmp"],"source_kind":"github","identifiers":["GHSA-383p-xqxx-rrmp","CVE-2016-3093"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:12:13.423Z","updated_at":"2026-09-25T12:11:37.678Z","epss_percentage":0.08443,"epss_percentile":0.94755,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zODNwLXhxeHgtcnJtcM4AAdBJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zODNwLXhxeHgtcnJtcM4AAdBJ","packages":[{"ecosystem":"maven","package_name":"ognl:ognl","versions":[{"first_patched_version":"3.0.12","vulnerable_version_range":"\u003c 3.0.12"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.24.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.3.24.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zODNwLXhxeHgtcnJtcM4AAdBJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wdm05LTI4OGMtdjV3cc4AAdBO","url":"https://github.com/advisories/GHSA-pvm9-288c-v5wq","title":"Remote Code Execution in Apache Struts","description":"XSLTResult allows for the location of a stylesheet being passed as a request parameter. In some circumstances this can be used to inject remotely executable code.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-17T03:42:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-3082","http://struts.apache.org/docs/s2-031.html","https://github.com/advisories/GHSA-pvm9-288c-v5wq"],"source_kind":"github","identifiers":["GHSA-pvm9-288c-v5wq","CVE-2016-3082"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.851Z","updated_at":"2026-09-24T15:11:22.623Z","epss_percentage":0.1917,"epss_percentile":0.97202,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wdm05LTI4OGMtdjV3cc4AAdBO","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wdm05LTI4OGMtdjV3cc4AAdBO","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.28.1","vulnerable_version_range":"\u003e= 2.3.28, \u003c 2.3.28.1"},{"first_patched_version":"2.3.24.3","vulnerable_version_range":"\u003e= 2.3.24, \u003c 2.3.24.3"},{"first_patched_version":"2.3.20.3","vulnerable_version_range":"\u003c 2.3.20.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wdm05LTI4OGMtdjV3cc4AAdBO/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qN2g2LXhyN2ctbTJjNc4AAcrC","url":"https://github.com/advisories/GHSA-j7h6-xr7g-m2c5","title":"Code injection in Apache Struts","description":"Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-17T03:28:23.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-4316","http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.html","http://struts.apache.org/release/2.3.x/docs/s2-019.html","https://github.com/apache/struts/commit/58947c3f85ae641c1a476316a2888e53605948d1","https://github.com/apache/struts/commit/c643336945dda84cbcdc8a39530baa24fede28c4","https://github.com/advisories/GHSA-j7h6-xr7g-m2c5"],"source_kind":"github","identifiers":["GHSA-j7h6-xr7g-m2c5","CVE-2013-4316"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.000Z","updated_at":"2026-09-25T19:10:25.255Z","epss_percentage":0.08401,"epss_percentile":0.94535,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qN2g2LXhyN2ctbTJjNc4AAcrC","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qN2g2LXhyN2ctbTJjNc4AAcrC","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-rest-plugin","versions":[{"first_patched_version":"2.3.15.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.15.2"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.15.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.15.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qN2g2LXhyN2ctbTJjNc4AAcrC/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycGo5LXI4OTctd2M2cc4AAcSx","url":"https://github.com/advisories/GHSA-rpj9-r897-wc6q","title":"Open redirect in Apache Struts","description":"The Struts 2 DefaultActionMapper used to support a method for short-circuit navigation state changes by prefixing parameters with \"redirect:\" or \"redirectAction:\", followed by a desired redirect target expression. This mechanism was intended to help with attaching navigational information to buttons within forms. Attackers could use this to redirect to arbitrary web sites and conduct phishing attacks.\n\nIn Struts 2 before 2.3.15.1 the information following \"redirect:\" or \"redirectAction:\" can easily be manipulated to redirect to an arbitrary location.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T03:13:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-2248","http://struts.apache.org/release/2.3.x/docs/s2-017.html","https://github.com/apache/struts/commit/3cfe34fefedcf0fdcfcb061c0aea34a715b7de6","https://github.com/apache/struts/commit/630e1ba065a8215c4e9ac03bfb09be9d655c2b6e","https://issues.apache.org/jira/browse/WW-4140","https://github.com/advisories/GHSA-rpj9-r897-wc6q"],"source_kind":"github","identifiers":["GHSA-rpj9-r897-wc6q","CVE-2013-2248"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.027Z","updated_at":"2026-08-15T20:14:51.448Z","epss_percentage":0.94654,"epss_percentile":0.99845,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycGo5LXI4OTctd2M2cc4AAcSx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycGo5LXI4OTctd2M2cc4AAcSx","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.15.1","vulnerable_version_range":"\u003c 2.3.15.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycGo5LXI4OTctd2M2cc4AAcSx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14Zzc1LTY4eDMtN3Azcc4AAa4P","url":"https://github.com/advisories/GHSA-xg75-68x3-7p3q","title":"Apache Struts vulnerable to possible DoS attack when using URLValidator","description":"The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.13 allows remote attackers to cause a denial of service via a null value for a URL field.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T02:16:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-4465","https://bugzilla.redhat.com/show_bug.cgi?id=1348253","https://struts.apache.org/docs/s2-041.html","http://jvn.jp/en/jp/JVN12352818/index.html","http://jvndb.jvn.jp/jvndb/JVNDB-2016-000114","http://www-01.ibm.com/support/docview.wss?uid=swg21987854","https://github.com/apache/struts/commit/a0fdca138feec2c2e94eb75ca1f8b76678b4d152","https://github.com/apache/struts/commit/eccc31ebce5430f9e91b9684c63eaaf885e603f9","https://github.com/advisories/GHSA-xg75-68x3-7p3q"],"source_kind":"github","identifiers":["GHSA-xg75-68x3-7p3q","CVE-2016-4465"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:52.973Z","updated_at":"2026-09-24T15:11:20.775Z","epss_percentage":0.10365,"epss_percentile":0.95509,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14Zzc1LTY4eDMtN3Azcc4AAa4P","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14Zzc1LTY4eDMtN3Azcc4AAa4P","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.13","vulnerable_version_range":"\u003e= 2.5.0, \u003c 2.5.13"},{"first_patched_version":"2.3.29","vulnerable_version_range":"\u003e= 2.3.20, \u003c 2.3.29"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14Zzc1LTY4eDMtN3Azcc4AAa4P/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14bTkyLXYybXEtODQycc4AAa4Q","url":"https://github.com/advisories/GHSA-xm92-v2mq-842q","title":"Apache Struts improper action name cleanup","description":"Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-17T02:16:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-4436","https://struts.apache.org/docs/s2-035.html","http://www-01.ibm.com/support/docview.wss?uid=ssg1S1009282","http://www-01.ibm.com/support/docview.wss?uid=swg21987854","http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html","https://github.com/apache/struts/commit/237432512df0e27013f7c7b9ab59fdce44ca34a5","https://github.com/apache/struts/commit/27ca165ddbf81c84bafbd083b99a18d89cc49ca7","https://web.archive.org/web/20161015140316/http://www.securityfocus.com/bid/91280/","https://github.com/advisories/GHSA-xm92-v2mq-842q"],"source_kind":"github","identifiers":["GHSA-xm92-v2mq-842q","CVE-2016-4436"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2024-01-04T19:05:46.672Z","updated_at":"2026-09-25T19:10:22.502Z","epss_percentage":0.06603,"epss_percentile":0.93543,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14bTkyLXYybXEtODQycc4AAa4Q","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14bTkyLXYybXEtODQycc4AAa4Q","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.1","vulnerable_version_range":"\u003e= 2.5-BETA1, \u003c 2.5.1"},{"first_patched_version":"2.3.29","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.29"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14bTkyLXYybXEtODQycc4AAa4Q/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ycnZoLXE1MzktcTMzds4AAaDY","url":"https://github.com/advisories/GHSA-2rvh-q539-q33v","title":"Cross-Site Request Forgery in Apache Struts","description":"The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-17T01:42:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2012-4386","https://exchange.xforce.ibmcloud.com/vulnerabilities/78182","https://issues.apache.org/jira/browse/WW-3858","http://struts.apache.org/2.x/docs/s2-010.html","http://www.openwall.com/lists/oss-security/2012/09/01/4","http://www.openwall.com/lists/oss-security/2012/09/01/5","https://github.com/advisories/GHSA-2rvh-q539-q33v"],"source_kind":"github","identifiers":["GHSA-2rvh-q539-q33v","CVE-2012-4386"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:53.190Z","updated_at":"2026-08-21T12:10:26.060Z","epss_percentage":0.0336,"epss_percentile":0.87766,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycnZoLXE1MzktcTMzds4AAaDY","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ycnZoLXE1MzktcTMzds4AAaDY","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.4.1","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.4.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycnZoLXE1MzktcTMzds4AAaDY/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xMmNnLXhmOXAtaDQ1N84AAYyu","url":"https://github.com/advisories/GHSA-q2cg-xf9p-h457","title":"Incomplete exclude pattern in Apache Struts","description":"The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to \"compromise internal state of an application\" via unspecified vectors. In Struts 2.3.20.1 a better set of exlude patterns was defined.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-17T00:50:08.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2015-1831","https://struts.apache.org/docs/s2-024.html","https://github.com/apache/struts/commit/d832747d647df343ed07a58b1b5e540a05a4d51b","https://github.com/advisories/GHSA-q2cg-xf9p-h457"],"source_kind":"github","identifiers":["GHSA-q2cg-xf9p-h457","CVE-2015-1831"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.055Z","updated_at":"2026-09-22T08:13:03.798Z","epss_percentage":0.06363,"epss_percentile":0.93099,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xMmNnLXhmOXAtaDQ1N84AAYyu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xMmNnLXhmOXAtaDQ1N84AAYyu","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.3.20.1","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.20.1"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20.1","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.20.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xMmNnLXhmOXAtaDQ1N84AAYyu/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cWdqLTltdmctMzkyOc4AAWri","url":"https://github.com/advisories/GHSA-4qgj-9mvg-3929","title":"Special top object can be used to access Struts' internals","description":"ValueStack defines special top object which represents root of execution context. It can be used to manipulate Struts' internals or can be used to affect container's settings. Applying better regex which includes pattern to exclude request parameters trying to use top object. This issue was patched in Struts 2.3.24.1.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T03:15:08.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2015-5209","https://security.netapp.com/advisory/ntap-20180629-0002/","https://struts.apache.org/docs/s2-026.html","https://github.com/advisories/GHSA-4qgj-9mvg-3929"],"source_kind":"github","identifiers":["GHSA-4qgj-9mvg-3929","CVE-2015-5209"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:53.009Z","updated_at":"2026-09-25T19:13:30.000Z","epss_percentage":0.09063,"epss_percentile":0.95056,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cWdqLTltdmctMzkyOc4AAWri","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cWdqLTltdmctMzkyOc4AAWri","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.24.1","vulnerable_version_range":"\u003c 2.3.24.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cWdqLTltdmctMzkyOc4AAWri/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04NnZxLThxaGMtNXJxd84AAWrf","url":"https://github.com/advisories/GHSA-86vq-8qhc-5rqw","title":"Apache Struts vulnerable to possible DoS attack when using URLValidator","description":"If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T03:15:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.9,"cvss_vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-8738","https://security.netapp.com/advisory/ntap-20180629-0003/","https://struts.apache.org/docs/s2-044.html","https://github.com/apache/struts/commit/554b9dddb0fbd1e581ef577dd62a7c22955ad0f6","https://github.com/advisories/GHSA-86vq-8qhc-5rqw"],"source_kind":"github","identifiers":["GHSA-86vq-8qhc-5rqw","CVE-2016-8738"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.019Z","updated_at":"2026-09-24T15:11:20.775Z","epss_percentage":0.03259,"epss_percentile":0.87818,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NnZxLThxaGMtNXJxd84AAWrf","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NnZxLThxaGMtNXJxd84AAWrf","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.13","vulnerable_version_range":"\u003e= 2.5.0, \u003c 2.5.13"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NnZxLThxaGMtNXJxd84AAWrf/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oNHY5LWpmMnItOWg2bc4AAWFk","url":"https://github.com/advisories/GHSA-h4v9-jf2r-9h6m","title":"Cross-Site Request Forgery in Apache Struts","description":"Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable \u003cs:token/\u003e values, which allows remote attackers to bypass the CSRF protection mechanism.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T02:50:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2014-7809","http://packetstormsecurity.com/files/129421/Apache-Struts-2.3.20-Security-Fixes.html","http://struts.apache.org/docs/s2-023.html","https://web.archive.org/web/20150201180327/http://www.securitytracker.com/id/1031309","https://web.archive.org/web/20150820131625/http://www.securityfocus.com/bid/71548","https://web.archive.org/web/20201023114849/http://www.securityfocus.com/archive/1/534175/100/0/threaded","https://github.com/apache/struts/commit/1f301038a751bf16e525607c3db513db835b2999","https://github.com/advisories/GHSA-h4v9-jf2r-9h6m"],"source_kind":"github","identifiers":["GHSA-h4v9-jf2r-9h6m","CVE-2014-7809"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.143Z","updated_at":"2026-09-22T20:14:55.559Z","epss_percentage":0.03514,"epss_percentile":0.88505,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNHY5LWpmMnItOWg2bc4AAWFk","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oNHY5LWpmMnItOWg2bc4AAWFk","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20","vulnerable_version_range":"\u003c 2.3.20"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNHY5LWpmMnItOWg2bc4AAWFk/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ncXFtLTU2NGYtdnZ4cc4AAUxj","url":"https://github.com/advisories/GHSA-gqqm-564f-vvxq","title":"Arbitrary code execution in Apache Struts 2","description":"Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T01:57:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-2134","https://cwiki.apache.org/confluence/display/WW/S2-015","http://security.gentoo.org/glsa/glsa-201409-04.xml","http://struts.apache.org/development/2.x/docs/s2-015.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://github.com/apache/struts/commit/01e6b251b4db78bfb7971033652e81d1af4cb3e0","https://github.com/apache/struts/commit/041206d2a693d02c0cb2e72765275e55ba14049f","https://github.com/apache/struts/commit/113c47082c09818bcef65acc436a2d0c7c47aa6c","https://github.com/apache/struts/commit/54e5c912ebd9a1599bfcf7a719da17c28127bbe3","https://github.com/apache/struts/commit/711cf0201cdd319a38cf29238913312355db29ba","https://github.com/apache/struts/commit/8b4fc81daeea3834bcbf73de5f48d0021917aa37","https://github.com/apache/struts/commit/cfb6e9afbae320a4dd5bdd655154ab9fe5a92c16","https://issues.apache.org/jira/browse/WW-4090","https://issues.apache.org/jira/browse/WW-4094","https://issues.apache.org/jira/browse/WW-4095","https://web.archive.org/web/20140226173351/http://www.securityfocus.com/bid/60346","https://web.archive.org/web/20140410223942/http://www.securityfocus.com/bid/64758","https://github.com/advisories/GHSA-gqqm-564f-vvxq"],"source_kind":"github","identifiers":["GHSA-gqqm-564f-vvxq","CVE-2013-2134"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.110Z","updated_at":"2026-09-22T08:13:05.459Z","epss_percentage":0.70211,"epss_percentile":0.99299,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncXFtLTU2NGYtdnZ4cc4AAUxj","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ncXFtLTU2NGYtdnZ4cc4AAUxj","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.3.14.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.3"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.14.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncXFtLTU2NGYtdnZ4cc4AAUxj/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12d2h2LWozNmctNXJtOM4AAUxp","url":"https://github.com/advisories/GHSA-vwhv-j36g-5rm8","title":"Cross-site Scripting in Apache Struts","description":"When the Struts2 debug mode is turned on, under certain conditions an arbitrary script may be executed in the 'Problem Report' screen. Also if JSP files are exposed to be accessed directly it's possible to execute an arbitrary script. \n\nIt is generally not advisable to have debug mode switched on outside of the development environment. Debug mode should always be turned off in production setup. Also never expose JSPs files directly and hide them inside WEB-INF folder or define dedicated security constraints to block access to raw JSP files.\n\nStruts \u003e= 2.3.20 is not vulnerable to this attack. We recommend upgrading to Struts 2.3.20 or higher.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T01:57:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2015-5169","https://bugzilla.redhat.com/show_bug.cgi?id=1260087","https://security.netapp.com/advisory/ntap-20180629-0003/","https://struts.apache.org/docs/s2-025.html","http://jvn.jp/en/jp/JVN95989300/index.html","http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000125.html","https://github.com/advisories/GHSA-vwhv-j36g-5rm8"],"source_kind":"github","identifiers":["GHSA-vwhv-j36g-5rm8","CVE-2015-5169"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.884Z","updated_at":"2026-09-25T19:13:28.392Z","epss_percentage":0.07533,"epss_percentile":0.9423,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12d2h2LWozNmctNXJtOM4AAUxp","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12d2h2LWozNmctNXJtOM4AAUxp","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20","vulnerable_version_range":"\u003c 2.3.20"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12d2h2LWozNmctNXJtOM4AAUxp/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wdzhyLXgycW0tM2g1bc4AAUxe","url":"https://github.com/advisories/GHSA-pw8r-x2qm-3h5m","title":"Arbitrary code execution in Apache Struts 2","description":"Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both \"${}\" and \"%{}\" sequences, which causes the OGNL code to be evaluated twice.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T01:57:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-2135","https://cwiki.apache.org/confluence/display/WW/S2-015","http://struts.apache.org/development/2.x/docs/s2-015.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://github.com/apache/struts/commit/01e6b251b4db78bfb7971033652e81d1af4cb3e0","https://github.com/apache/struts/commit/041206d2a693d02c0cb2e72765275e55ba14049f","https://github.com/apache/struts/commit/113c47082c09818bcef65acc436a2d0c7c47aa6c","https://github.com/apache/struts/commit/54e5c912ebd9a1599bfcf7a719da17c28127bbe3","https://github.com/apache/struts/commit/711cf0201cdd319a38cf29238913312355db29ba","https://github.com/apache/struts/commit/8b4fc81daeea3834bcbf73de5f48d0021917aa37","https://github.com/apache/struts/commit/cfb6e9afbae320a4dd5bdd655154ab9fe5a92c16","https://issues.apache.org/jira/browse/WW-4090","https://issues.apache.org/jira/browse/WW-4094","https://issues.apache.org/jira/browse/WW-4095","https://web.archive.org/web/20140410223942/http://www.securityfocus.com/bid/64758","https://github.com/advisories/GHSA-pw8r-x2qm-3h5m"],"source_kind":"github","identifiers":["GHSA-pw8r-x2qm-3h5m","CVE-2013-2135"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.127Z","updated_at":"2026-09-15T18:10:18.912Z","epss_percentage":0.13828,"epss_percentile":0.96041,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wdzhyLXgycW0tM2g1bc4AAUxe","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wdzhyLXgycW0tM2g1bc4AAUxe","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.3.14.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.3"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.14.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wdzhyLXgycW0tM2g1bc4AAUxe/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tM3g2LTl2NmgtNGcyOM4AAUxh","url":"https://github.com/advisories/GHSA-m3x6-9v6h-4g28","title":"Cross-site Scripting in Apache Struts","description":"Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T01:57:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-4003","https://issues.apache.org/jira/browse/WW-4507","http://struts.apache.org/docs/s2-028.html","https://github.com/apache/struts/commit/4720f46a63caaf9db97ba27dc51ac5ad21e66bdc","https://github.com/apache/struts/commit/5421930b49822606792f36653b17d3d95ef106f9","https://github.com/apache/struts/commit/72471d7075681bea52046645ad7aa34e9c53751e","https://github.com/apache/struts/commit/76f188406eb9f17a06afcb5f49f0c44d749da0d2","https://github.com/apache/struts/commit/a89bbe22cd2461748d595a89a254de888a415e6c","https://web.archive.org/web/20161119142317/http://www.securityfocus.com/bid/86311","https://web.archive.org/web/20161221184936/http://www.securitytracker.com/id/1035268","https://github.com/advisories/GHSA-m3x6-9v6h-4g28"],"source_kind":"github","identifiers":["GHSA-m3x6-9v6h-4g28","CVE-2016-4003"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.135Z","updated_at":"2026-09-24T15:11:22.623Z","epss_percentage":0.11562,"epss_percentile":0.95836,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tM3g2LTl2NmgtNGcyOM4AAUxh","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tM3g2LTl2NmgtNGcyOM4AAUxh","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.28","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.28"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tM3g2LTl2NmgtNGcyOM4AAUxh/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1td3J4LWh4NngtM2hods4AAUpl","url":"https://github.com/advisories/GHSA-mwrx-hx6x-3hhv","title":"Apache Struts Code injection due to conversion error","description":"Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T01:51:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2012-0838","https://issues.apache.org/jira/browse/WW-3668","http://jvn.jp/en/jp/JVN79099262/index.html","http://jvndb.jvn.jp/jvndb/JVNDB-2012-000012","http://struts.apache.org/2.3.1.2/docs/s2-007.html","https://github.com/apache/struts/commit/25e50069d60434a30395e3a98357ffba2bed427e","https://github.com/apache/struts/commit/5f54b8d087f5125d96838aafa5f64c2190e6885b","https://github.com/apache/struts/commit/b4265d369dc29d57a9f2846a85b26598e83f3892","https://github.com/advisories/GHSA-mwrx-hx6x-3hhv"],"source_kind":"github","identifiers":["GHSA-mwrx-hx6x-3hhv","CVE-2012-0838"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:52.893Z","updated_at":"2026-09-25T19:12:10.478Z","epss_percentage":0.1388,"epss_percentile":0.9608,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1td3J4LWh4NngtM2hods4AAUpl","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1td3J4LWh4NngtM2hods4AAUpl","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.2.3.1","vulnerable_version_range":"\u003c 2.2.3.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1td3J4LWh4NngtM2hods4AAUpl/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04NjR3LXI1cWotaDZmas4AAThz","url":"https://github.com/advisories/GHSA-864w-r5qj-h6fj","title":"Apache Struts forced double OGNL evaluation","description":"Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a \"%{}\" sequence in a tag attribute, aka forced double OGNL evaluation.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T01:05:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-4461","https://struts.apache.org/docs/s2-036.html","https://security.netapp.com/advisory/ntap-20180629-0004","https://github.com/advisories/GHSA-864w-r5qj-h6fj"],"source_kind":"github","identifiers":["GHSA-864w-r5qj-h6fj","CVE-2016-4461"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-04-23T03:08:36.794Z","updated_at":"2026-09-23T15:09:15.920Z","epss_percentage":0.08085,"epss_percentile":0.94553,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NjR3LXI1cWotaDZmas4AAThz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NjR3LXI1cWotaDZmas4AAThz","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.29","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.29"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NjR3LXI1cWotaDZmas4AAThz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wcmp2LWpqMjYtd2Y4aM4AATRB","url":"https://github.com/advisories/GHSA-prjv-jj26-wf8h","title":"ClassLoader manipulation in Apache Struts","description":"ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to \"manipulate\" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:54:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2014-0112","https://access.redhat.com/errata/RHSA-2019:0910","https://bugzilla.redhat.com/show_bug.cgi?id=1091939","https://cwiki.apache.org/confluence/display/WW/S2-021","http://jvn.jp/en/jp/JVN19294237/index.html","http://jvndb.jvn.jp/jvndb/JVNDB-2014-000045","http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html","http://www-01.ibm.com/support/docview.wss?uid=swg21676706","http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html","http://www.vmware.com/security/advisories/VMSA-2014-0007.html","https://github.com/advisories/GHSA-prjv-jj26-wf8h"],"source_kind":"github","identifiers":["GHSA-prjv-jj26-wf8h","CVE-2014-0112"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.911Z","updated_at":"2026-08-15T20:14:49.283Z","epss_percentage":0.97915,"epss_percentile":0.99903,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcmp2LWpqMjYtd2Y4aM4AATRB","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wcmp2LWpqMjYtd2Y4aM4AATRB","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20","vulnerable_version_range":"\u003c 2.3.20"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcmp2LWpqMjYtd2Y4aM4AATRB/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13aG1xLXY5NHEtMzRwOc4AATQ8","url":"https://github.com/advisories/GHSA-whmq-v94q-34p9","title":"Improper Control of Generation of Code in Apache Struts","description":"Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:54:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-1965","https://bugzilla.redhat.com/show_bug.cgi?id=967655","http://struts.apache.org/development/2.x/docs/s2-012.html","https://web.archive.org/web/20140227231557/http://www.securityfocus.com/bid/60082","https://github.com/apache/struts/commit/7e6f641ebb142663cbd1653dc49bed725edf7f56","https://github.com/advisories/GHSA-whmq-v94q-34p9"],"source_kind":"github","identifiers":["GHSA-whmq-v94q-34p9","CVE-2013-1965"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:12:11.827Z","updated_at":"2026-08-21T12:08:53.585Z","epss_percentage":0.93527,"epss_percentile":0.99832,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13aG1xLXY5NHEtMzRwOc4AATQ8","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13aG1xLXY5NHEtMzRwOc4AATQ8","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.14.3","vulnerable_version_range":"\u003c 2.3.14.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13aG1xLXY5NHEtMzRwOc4AATQ8/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Mzd3LW1oNTgtY3hqcM4AATQ_","url":"https://github.com/advisories/GHSA-737w-mh58-cxjp","title":"Arbitrary code execution in Apache Struts","description":"Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:54:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2013-1966","https://bugzilla.redhat.com/show_bug.cgi?id=967656","https://cwiki.apache.org/confluence/display/WW/S2-013","http://struts.apache.org/development/2.x/docs/s2-013.html","https://github.com/apache/struts/commit/7e6f641ebb142663cbd1653dc49bed725edf7f56","https://github.com/advisories/GHSA-737w-mh58-cxjp"],"source_kind":"github","identifiers":["GHSA-737w-mh58-cxjp","CVE-2013-1966"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:52.938Z","updated_at":"2026-08-21T12:08:53.583Z","epss_percentage":0.73705,"epss_percentile":0.99431,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Mzd3LW1oNTgtY3hqcM4AATQ_","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Mzd3LW1oNTgtY3hqcM4AATQ_","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.3.14.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.2"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.14.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Mzd3LW1oNTgtY3hqcM4AATQ_/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12cndjLXFqbXctNXJqbc4AATRA","url":"https://github.com/advisories/GHSA-vrwc-qjmw-5rjm","title":"ClassLoader manipulation in Apache Struts","description":"The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to \"manipulate\" the ClassLoader via the class parameter, which is passed to the getClass method.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T00:54:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2014-0094","http://jvn.jp/en/jp/JVN19294237/index.html","http://jvndb.jvn.jp/jvndb/JVNDB-2014-000045","http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html","http://struts.apache.org/release/2.3.x/docs/s2-020.html","http://www-01.ibm.com/support/docview.wss?uid=swg21676706","http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm","http://www.konakart.com/downloads/ver-7-3-0-0-whats-new","http://www.vmware.com/security/advisories/VMSA-2014-0007.html","https://github.com/apache/struts/commit/2e2da292166adbc78c4cb1e308b30ddb4fba6d3f","https://github.com/apache/struts/commit/6315241719be167542962da436b38782ed730c62","https://github.com/advisories/GHSA-vrwc-qjmw-5rjm"],"source_kind":"github","identifiers":["GHSA-vrwc-qjmw-5rjm","CVE-2014-0094"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:52.929Z","updated_at":"2026-09-25T19:10:25.254Z","epss_percentage":0.99566,"epss_percentile":0.99946,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cndjLXFqbXctNXJqbc4AATRA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12cndjLXFqbXctNXJqbc4AATRA","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.3.16.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.16.2"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.16.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.16.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cndjLXFqbXctNXJqbc4AATRA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zYzVjLXhycTQtcWhyOM4AATQ2","url":"https://github.com/advisories/GHSA-3c5c-xrq4-qhr8","title":"ClassLoader manipulation in Apache Struts","description":"CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to \"manipulate\" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:54:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2014-0113","https://cwiki.apache.org/confluence/display/WW/S2-021","http://www-01.ibm.com/support/docview.wss?uid=swg21676706","https://github.com/advisories/GHSA-3c5c-xrq4-qhr8"],"source_kind":"github","identifiers":["GHSA-3c5c-xrq4-qhr8","CVE-2014-0113"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.946Z","updated_at":"2026-08-15T20:19:06.864Z","epss_percentage":0.7783,"epss_percentile":0.99521,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zYzVjLXhycTQtcWhyOM4AATQ2","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zYzVjLXhycTQtcWhyOM4AATQ2","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20","vulnerable_version_range":"\u003c 2.3.20"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zYzVjLXhycTQtcWhyOM4AATQ2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04YzZqLWZmbWYtcTZ2bc4AATRI","url":"https://github.com/advisories/GHSA-8c6j-ffmf-q6vm","title":"Apache Struts RCE Vulnerability","description":"Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:54:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-3081","https://struts.apache.org/docs/s2-032.html","https://www.exploit-db.com/exploits/39756/","http://packetstormsecurity.com/files/136856/Apache-Struts-2.3.28-Dynamic-Method-Invocation-Remote-Code-Execution.html","http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en","http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html","http://www.rapid7.com/db/modules/exploit/linux/http/struts_dmi_exec","http://www.rapid7.com/db/modules/exploit/multi/http/struts_dmi_exec","https://web.archive.org/web/20210123152457/http://www.securityfocus.com/bid/91787","https://web.archive.org/web/20210225192113/http://www.securityfocus.com/bid/87327","https://web.archive.org/web/20210226011418/http://www.securitytracker.com/id/1035665","https://github.com/advisories/GHSA-8c6j-ffmf-q6vm"],"source_kind":"github","identifiers":["GHSA-8c6j-ffmf-q6vm","CVE-2016-3081"],"repository_url":null,"blast_radius":0.0,"created_at":"2023-07-28T22:03:40.898Z","updated_at":"2026-09-24T15:11:57.470Z","epss_percentage":0.93352,"epss_percentile":0.99835,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04YzZqLWZmbWYtcTZ2bc4AATRI","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04YzZqLWZmbWYtcTZ2bc4AATRI","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.24.3","vulnerable_version_range":"\u003e= 2.3.21, \u003c= 2.3.24.2"},{"first_patched_version":"2.3.28.1","vulnerable_version_range":"\u003e= 2.3.25, \u003c= 2.3.28"},{"first_patched_version":"2.3.20.3","vulnerable_version_range":"\u003e= 2.3.19, \u003c= 2.3.20.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04YzZqLWZmbWYtcTZ2bc4AATRI/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tbWo2LWNqajQtaHByNc4AATRH","url":"https://github.com/advisories/GHSA-mmj6-cjj4-hpr5","title":"Apache Struts vulnerable to arbitrary remote code execution due to improper input validation","description":"Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an `!` (exclamation mark) operator to the REST Plugin.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-14T00:54:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-3087","https://www.exploit-db.com/exploits/39919/","http://struts.apache.org/docs/s2-033.html","http://www-01.ibm.com/support/docview.wss?uid=swg21987854","https://github.com/apache/struts/commit/6bd694b7980494c12d49ca1bf39f12aec3e03e2f","https://web.archive.org/web/20160616082237/http://www.securitytracker.com/id/1036017","https://web.archive.org/web/20160728170709/http://www.securityfocus.com/bid/90960","https://github.com/advisories/GHSA-mmj6-cjj4-hpr5"],"source_kind":"github","identifiers":["GHSA-mmj6-cjj4-hpr5","CVE-2016-3087"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-12-29T18:05:32.520Z","updated_at":"2026-09-24T15:11:22.620Z","epss_percentage":0.81873,"epss_percentile":0.99632,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tbWo2LWNqajQtaHByNc4AATRH","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tbWo2LWNqajQtaHByNc4AATRH","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.28.1","vulnerable_version_range":"\u003e= 2.3.25, \u003c 2.3.28.1"},{"first_patched_version":"2.3.24.3","vulnerable_version_range":"\u003e= 2.3.21, \u003c 2.3.24.3"},{"first_patched_version":"2.3.20.3","vulnerable_version_range":"\u003e= 2.3.19, \u003c 2.3.20.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tbWo2LWNqajQtaHByNc4AATRH/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1obWhxLTM4MnEtbXA1Ns4AATQ0","url":"https://github.com/advisories/GHSA-hmhq-382q-mp56","title":"ClassLoader manipulation in Apache Struts","description":"CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to \"manipulate\" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:54:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2014-0116","http://struts.apache.org/release/2.3.x/docs/s2-022.html","http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm","https://github.com/apache/struts/commit/1a668af7f1ffccea4a3b46d8d8c1fe1c7331ff02","https://github.com/advisories/GHSA-hmhq-382q-mp56"],"source_kind":"github","identifiers":["GHSA-hmhq-382q-mp56","CVE-2014-0116"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:52.955Z","updated_at":"2026-09-22T08:13:03.798Z","epss_percentage":0.06569,"epss_percentile":0.93505,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obWhxLTM4MnEtbXA1Ns4AATQ0","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1obWhxLTM4MnEtbXA1Ns4AATQ0","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.20","vulnerable_version_range":"\u003c 2.3.20"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obWhxLTM4MnEtbXA1Ns4AATQ0/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cHJqLXZ3OWotdjZwcs4AATRG","url":"https://github.com/advisories/GHSA-4prj-vw9j-v6pr","title":"Arbitrary code execution in Apache Struts 2","description":"The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-14T00:54:13.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-4438","https://bugzilla.redhat.com/show_bug.cgi?id=1348238","https://struts.apache.org/docs/s2-037.html","http://jvn.jp/en/jp/JVN07710476/index.html","http://jvndb.jvn.jp/jvndb/JVNDB-2016-000110","https://github.com/apache/struts/commit/6d7ac40dcede1793a4534a3dc249fd562d495e8c","https://github.com/apache/struts/commit/76eb8f38a33ad0f1f48464ee1311559c8d52dd6d","https://github.com/apache/struts/commit/c9c21378f2fb2ff21355c128c45e106ebd87ad7c","https://github.com/apache/struts/commit/deefeffd11425f0cd0b797cd86a9b3550234262b","https://github.com/advisories/GHSA-4prj-vw9j-v6pr"],"source_kind":"github","identifiers":["GHSA-4prj-vw9j-v6pr","CVE-2016-4438"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.236Z","updated_at":"2026-09-24T15:11:22.621Z","epss_percentage":0.16742,"epss_percentile":0.96894,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cHJqLXZ3OWotdjZwcs4AATRG","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cHJqLXZ3OWotdjZwcs4AATRG","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-rest-plugin","versions":[{"first_patched_version":"2.3.29","vulnerable_version_range":"\u003e= 2.3.19, \u003c 2.3.29"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.29","vulnerable_version_range":"\u003e= 2.3.19, \u003c 2.3.29"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cHJqLXZ3OWotdjZwcs4AATRG/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04NzZwLTR3Z2MtNzVyeM4AATMB","url":"https://github.com/advisories/GHSA-876p-4wgc-75rx","title":"Apache Struts RCE Vulnerability","description":"Apache Struts 2.x before 2.3.20.3, 2.3.24.3, and 2.3.28 allows remote attackers to execute arbitrary code via a `%{}` sequence in a tag attribute, aka forced double OGNL evaluation.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T00:52:12.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-0785","http://struts.apache.org/docs/s2-029.html","https://web.archive.org/web/20210123095715/http://www.securityfocus.com/bid/85066","https://web.archive.org/web/20220118185853/http://www.securitytracker.com/id/1035271","https://github.com/apache/struts/commit/15857a69e7baf3675804495a5954cd0756ac8364","https://github.com/advisories/GHSA-876p-4wgc-75rx"],"source_kind":"github","identifiers":["GHSA-876p-4wgc-75rx","CVE-2016-0785"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-07-28T22:03:40.885Z","updated_at":"2026-09-24T15:11:22.624Z","epss_percentage":0.08884,"epss_percentile":0.94983,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NzZwLTR3Z2MtNzVyeM4AATMB","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NzZwLTR3Z2MtNzVyeM4AATMB","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.24.3","vulnerable_version_range":"\u003e= 2.3.24, \u003c 2.3.24.3"},{"first_patched_version":"2.3.20.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.20.3"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NzZwLTR3Z2MtNzVyeM4AATMB/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Z2htLXJwYzctcDdnNc34jQ","url":"https://github.com/advisories/GHSA-7ghm-rpc7-p7g5","title":"Code injection in Apache Struts","description":"A vulnerability introduced by forcing parameter inclusion in the URL and Anchor Tag allows remote command execution, session access and manipulation and XSS attacks.\n\nboth the s:url and s:a tag provide an includeParams attribute.\n\nThe main scope of that attribute is to understand whether includes http request parameter or not.\n\nThe allowed values of includeParams are:\n\n    none - include no parameters in the URL (default)\n    get - include only GET parameters in the URL\n    all - include both GET and POST parameters in the URL\n\nA request that included a specially crafted request parameter could be used to inject arbitrary OGNL code into the stack, afterward used as request parameter of an URL or A tag , which will cause a further evaluation.\n\nThe second evaluation happens when the URL/A tag tries to resolve every parameters present in the original request.\nThis lets malicious users put arbitrary OGNL statements into any request parameter (not necessarily managed by the code) and have it evaluated as an OGNL expression to enable method execution and execute arbitrary methods, bypassing Struts and OGNL library protections.\n\nThe issue was originally addressed by Struts 2.3.14.1 and Security Announcement [S2-013](https://cwiki.apache.org/confluence/display/WW/S2-013). However, the solution introduced with 2.3.14.1 did not address all possible attack vectors, such that every version of Struts 2 before 2.3.14.2 is still vulnerable to such attacks.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-13T01:16:08.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2013-2115","https://bugzilla.redhat.com/show_bug.cgi?id=967656","https://cwiki.apache.org/confluence/display/WW/S2-014","http://struts.apache.org/development/2.x/docs/s2-014.html","https://cwiki.apache.org/confluence/display/WW/S2-013","https://github.com/apache/struts/commit/d7804297e319c7a12245e1b536e565fcea6d650","https://github.com/apache/struts/commit/d934c6e7430b7b98e43a0a085a2304bd31a75c3d","https://github.com/apache/struts/commit/ea96d18d0f75c390d2595648efa3563785c272c6","https://github.com/apache/struts/commit/fed4f8e8a4ec69b5e7612b92d8ce3e476680474","https://issues.apache.org/jira/browse/WW-4063","https://web.archive.org/web/20140212000331/http://www.securityfocus.com/bid/60167","https://github.com/advisories/GHSA-7ghm-rpc7-p7g5"],"source_kind":"github","identifiers":["GHSA-7ghm-rpc7-p7g5","CVE-2013-2115"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:51.468Z","updated_at":"2026-09-15T18:10:18.915Z","epss_percentage":0.74636,"epss_percentile":0.99458,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Z2htLXJwYzctcDdnNc34jQ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Z2htLXJwYzctcDdnNc34jQ","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.3.14.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.2"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.14.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.14.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Z2htLXJwYzctcDdnNc34jQ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14NWZjLXBncHgtNTlqNc32hw","url":"https://github.com/advisories/GHSA-x5fc-pgpx-59j5","title":"Server side object manipulation in Apache Struts","description":"OGNL provides, among other features, extensive expression evaluation capabilities. This vulnerability allows a malicious user to bypass the '#'-usage protection built into the ParametersInterceptor, thus being able to manipulate server side context objects. This behavior was already addressed in [S2-003](https://cwiki.apache.org/confluence/display/WW/S2-003), but it turned out that the resulting fix based on whitelisting acceptable parameter names closed the vulnerability only partially.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-13T01:14:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2010-1870","http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html","http://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-06-16","http://packetstormsecurity.com/files/159643/LISTSERV-Maestro-9.0-8-Remote-Code-Execution.html","http://seclists.org/fulldisclosure/2010/Jul/183","http://seclists.org/fulldisclosure/2020/Oct/23","http://struts.apache.org/2.2.1/docs/s2-005.html","http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140709-struts2","https://cwiki.apache.org/confluence/display/WW/S2-003","https://github.com/advisories/GHSA-x5fc-pgpx-59j5"],"source_kind":"github","identifiers":["GHSA-x5fc-pgpx-59j5","CVE-2010-1870"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:53.220Z","updated_at":"2026-08-21T12:10:16.419Z","epss_percentage":0.92015,"epss_percentile":0.99812,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14NWZjLXBncHgtNTlqNc32hw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14NWZjLXBncHgtNTlqNc32hw","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.2.1","vulnerable_version_range":"\u003c 2.2.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14NWZjLXBncHgtNTlqNc32hw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00N3FwLTh2OWctMzlocM32gA","url":"https://github.com/advisories/GHSA-47qp-8v9g-39hp","title":"Code injection in Apache Struts","description":"The Struts 2 DefaultActionMapper supports a method for short-circuit navigation state changes by prefixing parameters with \"action:\" or \"redirect:\", followed by a desired navigational target expression. This mechanism was intended to help with attaching navigational information to buttons within forms.\n\nIn Struts 2 before 2.3.15.1 the information following \"action:\", \"redirect:\" or \"redirectAction:\" is not properly sanitized. Since said information will be evaluated as OGNL expression against the value stack, this introduces the possibility to inject server side code.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-13T01:14:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2013-2251","https://exchange.xforce.ibmcloud.com/vulnerabilities/90392","http://archiva.apache.org/security.html","http://cxsecurity.com/issue/WLB-2014010087","http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Execution.html","http://seclists.org/fulldisclosure/2013/Oct/96","http://seclists.org/oss-sec/2014/q1/89","http://struts.apache.org/release/2.3.x/docs/s2-016.html","http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2","http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html","https://github.com/apache/struts/commit/3cfe34fefedcf0fdcfcb061c0aea34a715b7de6","https://github.com/apache/struts/commit/630e1ba065a8215c4e9ac03bfb09be9d655c2b6e","https://issues.apache.org/jira/browse/WW-4140","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2251","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","https://github.com/advisories/GHSA-47qp-8v9g-39hp"],"source_kind":"github","identifiers":["GHSA-47qp-8v9g-39hp","CVE-2013-2251"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:11:53.229Z","updated_at":"2026-08-15T20:17:19.555Z","epss_percentage":0.99998,"epss_percentile":0.9999,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00N3FwLTh2OWctMzlocM32gA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00N3FwLTh2OWctMzlocM32gA","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.15.1","vulnerable_version_range":"\u003c 2.3.15.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00N3FwLTh2OWctMzlocM32gA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00d3JyLTloNXItbTkyd83e2w","url":"https://github.com/advisories/GHSA-4wrr-9h5r-m92w","title":"Apache Struts Remote Java Code Execution","description":"The `ExceptionDelegator` component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-04T00:29:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2012-0391","https://issues.apache.org/jira/browse/WW-3668","https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt","http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html","http://struts.apache.org/2.x/docs/s2-008.html","http://struts.apache.org/2.x/docs/version-notes-2311.html","http://www.exploit-db.com/exploits/18329","https://github.com/apache/struts/commit/25e50069d60434a30395e3a98357ffba2bed427e","https://github.com/apache/struts/commit/5f54b8d087f5125d96838aafa5f64c2190e6885b","https://github.com/apache/struts/commit/b4265d369dc29d57a9f2846a85b26598e83f3892","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0391","http://secunia.com/advisories/47393","https://github.com/advisories/GHSA-4wrr-9h5r-m92w"],"source_kind":"github","identifiers":["GHSA-4wrr-9h5r-m92w","CVE-2012-0391"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-08-29T21:05:27.791Z","updated_at":"2026-09-25T19:10:25.262Z","epss_percentage":0.75599,"epss_percentile":0.99504,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00d3JyLTloNXItbTkyd83e2w","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00d3JyLTloNXItbTkyd83e2w","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.2.3.1","vulnerable_version_range":"\u003c 2.2.3.1"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.2.3.1","vulnerable_version_range":"\u003c 2.2.3.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00d3JyLTloNXItbTkyd83e2w/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ycHBwLXhqMzQtdnZmN83e3A","url":"https://github.com/advisories/GHSA-2ppp-xj34-vvf7","title":"Apache Struts's CookieInterceptor component does not use the parameter-name whitelist","description":"The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-04T00:29:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2012-0392","https://lists.immunityinc.com/pipermail/dailydave/2012-January/000011.html","http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html","http://struts.apache.org/2.x/docs/s2-008.html","http://struts.apache.org/2.x/docs/version-notes-2311.html","http://www.exploit-db.com/exploits/18329","https://github.com/apache/struts/commit/25e50069d60434a30395e3a98357ffba2bed427e","https://web.archive.org/web/20120612142634/https://sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt","https://web.archive.org/web/20140723153720/http://secunia.com/advisories/47393/","https://github.com/advisories/GHSA-2ppp-xj34-vvf7"],"source_kind":"github","identifiers":["GHSA-2ppp-xj34-vvf7","CVE-2012-0392"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2023-12-27T21:05:46.674Z","updated_at":"2026-08-28T18:08:51.708Z","epss_percentage":0.97534,"epss_percentile":0.99898,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycHBwLXhqMzQtdnZmN83e3A","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ycHBwLXhqMzQtdnZmN83e3A","packages":[{"ecosystem":"maven","package_name":"org.apache.struts.xwork:xwork-core","versions":[{"first_patched_version":"2.2.3.1","vulnerable_version_range":"\u003c 2.2.3.1"}],"purl":null},{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.2.3.1","vulnerable_version_range":"\u003c 2.2.3.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycHBwLXhqMzQtdnZmN83e3A/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04bTVxLWNycXEtNnBtZs1AOA","url":"https://github.com/advisories/GHSA-8m5q-crqq-6pmf","title":"Unrestricted Upload of File with Dangerous Type in Apache Struts2","description":"A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. A patch exists as of version 2.5.22.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-04-23T00:40:23.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2012-1592","https://access.redhat.com/security/cve/cve-2012-1592","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1592","https://lists.apache.org/thread.html/r348ed455a140273c40b974f0615dee692f7c9b26c6de2118b4280ef2@%3Cissues.struts.apache.org%3E","https://lists.apache.org/thread.html/r593ebb2f4c95b064e6901fd273eff256c493db952bdb484395948ffc@%3Cissues.struts.apache.org%3E","https://lists.apache.org/thread.html/r93c4e3f6cb138cd117c739714f07e47af547183ba099ba46be2b2a5b@%3Cissues.struts.apache.org%3E","https://security-tracker.debian.org/tracker/CVE-2012-1592","https://github.com/apache/struts/blob/master/core/src/main/resources/struts-default.xml#L39-L76","https://issues.apache.org/jira/browse/WW-5055","https://seclists.org/bugtraq/2012/Mar/110","https://struts.apache.org/security/#internal-security-mechanism","https://lists.apache.org/thread.html/r348ed455a140273c40b974f0615dee692f7c9b26c6de2118b4280ef2%40%3Cissues.struts.apache.org%3E","https://lists.apache.org/thread.html/r593ebb2f4c95b064e6901fd273eff256c493db952bdb484395948ffc%40%3Cissues.struts.apache.org%3E","https://lists.apache.org/thread.html/r93c4e3f6cb138cd117c739714f07e47af547183ba099ba46be2b2a5b%40%3Cissues.struts.apache.org%3E","https://www.openwall.com/lists/oss-security/2012/03/28/12","https://github.com/advisories/GHSA-8m5q-crqq-6pmf"],"source_kind":"github","identifiers":["GHSA-8m5q-crqq-6pmf","CVE-2012-1592"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:12:10.832Z","updated_at":"2026-08-15T20:19:50.711Z","epss_percentage":0.2855,"epss_percentile":0.97886,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04bTVxLWNycXEtNnBtZs1AOA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04bTVxLWNycXEtNnBtZs1AOA","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.22","vulnerable_version_range":"\u003e= 2.0, \u003c 2.5.22"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04bTVxLWNycXEtNnBtZs1AOA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qNjhmLThoNnAtOWg1cc0-5A","url":"https://github.com/advisories/GHSA-j68f-8h6p-9h5q","title":"Struts ParameterInterceptor vulnerability allows remote command execution","description":"Regular expression in ParametersInterceptor matches `top['foo'](0)` as a valid expression, which OGNL treats as `(top['foo'])(0)` and evaluates the value of 'foo' action parameter as an OGNL expression. This lets malicious users put arbitrary OGNL statements into any String variable exposed by an action and have it evaluated as an OGNL expression and since OGNL statement is in HTTP parameter value attacker can use blacklisted characters (e.g. #) to disable method execution and execute arbitrary methods, bypassing the ParametersInterceptor and OGNL library protections.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-04-22T00:24:08.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2011-3923","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3923","https://exchange.xforce.ibmcloud.com/vulnerabilities/72585","https://security-tracker.debian.org/tracker/CVE-2011-3923","http://struts.apache.org/development/2.x/docs/s2-009.html","https://web.archive.org/web/20140725074137/http://seclists.org/fulldisclosure/2014/Jul/38","http://blog.o0o.nu/2012/01/cve-2011-3923-yet-another-struts2.html","https://github.com/advisories/GHSA-j68f-8h6p-9h5q"],"source_kind":"github","identifiers":["GHSA-j68f-8h6p-9h5q","CVE-2011-3923"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:11:52.812Z","updated_at":"2026-08-21T12:10:24.537Z","epss_percentage":0.89492,"epss_percentile":0.99775,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qNjhmLThoNnAtOWg1cc0-5A","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qNjhmLThoNnAtOWg1cc0-5A","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.1.2","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.3.1.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qNjhmLThoNnAtOWg1cc0-5A/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12OGo2LTZjMnItcjI3Y807Ew","url":"https://github.com/advisories/GHSA-v8j6-6c2r-r27c","title":"Expression Language Injection in Apache Struts","description":"The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-04-13T00:00:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-31805","https://cwiki.apache.org/confluence/display/WW/S2-062","http://www.openwall.com/lists/oss-security/2022/04/12/6","https://security.netapp.com/advisory/ntap-20220420-0001/","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/advisories/GHSA-v8j6-6c2r-r27c"],"source_kind":"github","identifiers":["GHSA-v8j6-6c2r-r27c","CVE-2021-31805"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:12:30.112Z","updated_at":"2026-08-15T20:20:30.827Z","epss_percentage":0.85433,"epss_percentile":0.997,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12OGo2LTZjMnItcjI3Y807Ew","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12OGo2LTZjMnItcjI3Y807Ew","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.30","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.5.30"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12OGo2LTZjMnItcjI3Y807Ew/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjMzUtcTM2OS00NXB2","url":"https://github.com/advisories/GHSA-jc35-q369-45pv","title":"Remote code execution in Apache Struts","description":"Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-02-09T22:51:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2020-17530","https://cwiki.apache.org/confluence/display/WW/S2-061","https://www.oracle.com/security-alerts/cpujan2021.html","http://jvn.jp/en/jp/JVN43969166/index.html","http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","http://www.openwall.com/lists/oss-security/2022/04/12/6","https://www.oracle.com/security-alerts/cpuapr2022.html","https://security.netapp.com/advisory/ntap-20210115-0005","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17530","https://github.com/advisories/GHSA-jc35-q369-45pv"],"source_kind":"github","identifiers":["GHSA-jc35-q369-45pv","CVE-2020-17530"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:13:07.829Z","updated_at":"2026-09-03T07:15:34.567Z","epss_percentage":0.95931,"epss_percentile":0.99871,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjMzUtcTM2OS00NXB2","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjMzUtcTM2OS00NXB2","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.26","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.5.26"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpjMzUtcTM2OS00NXB2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13cDRoLXB2Z3ctNTcyN80Y7Q","url":"https://github.com/advisories/GHSA-wp4h-pvgw-5727","title":"Improperly Controlled Modification of Dynamically-Determined Object Attributes in Apache Struts","description":"Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2021-12-02T14:50:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2019-0230","https://cwiki.apache.org/confluence/display/ww/s2-059","https://launchpad.support.sap.com/#/notes/2982840","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922@%3Cannounce.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","http://packetstormsecurity.com/files/160108/Apache-Struts-2.5.20-Double-OGNL-Evaluation.html","http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html","https://github.com/advisories/GHSA-wp4h-pvgw-5727"],"source_kind":"github","identifiers":["GHSA-wp4h-pvgw-5727","CVE-2019-0230"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:12:41.508Z","updated_at":"2026-09-25T19:14:50.156Z","epss_percentage":0.97399,"epss_percentile":0.99893,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cDRoLXB2Z3ctNTcyN80Y7Q","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13cDRoLXB2Z3ctNTcyN80Y7Q","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.22","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.5.22"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cDRoLXB2Z3ctNTcyN80Y7Q/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNyNmotM2pwOS1ydzY1","url":"https://github.com/advisories/GHSA-cr6j-3jp9-rw65","title":"Apache Struts vulnerable to remote command execution (RCE) due to improper input validation","description":"Apache Struts contains a Remote Code Execution when using results with no namespace and it's upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set,  and it's upper actions have no or wildcard namespace.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2018-10-18T19:24:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2018-11776","https://cwiki.apache.org/confluence/display/WW/S2-057","https://github.com/hook-s3c/CVE-2018-11776-Python-PoC","https://lgtm.com/blog/apache_struts_CVE-2018-11776","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-005.txt","http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html","https://github.com/apache/struts/commit/6e87474f9ad0549f07dd2c37d50a9ccd0977c6e","https://web.archive.org/web/20180822160726/http://www.securityfocus.com/bid/105125","https://web.archive.org/web/20200807025819/http://www.securitytracker.com/id/1041888","https://web.archive.org/web/20201208145803/https://securitytracker.com/id/1041547","https://www.exploit-db.com/exploits/45367","https://www.exploit-db.com/exploits/45262","https://www.exploit-db.com/exploits/45260","https://security.netapp.com/advisory/ntap-20181018-0002","https://security.netapp.com/advisory/ntap-20180822-0001","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E","http://www.securityfocus.com/bid/105125","http://www.securitytracker.com/id/1041547","http://www.securitytracker.com/id/1041888","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776","https://github.com/advisories/GHSA-cr6j-3jp9-rw65"],"source_kind":"github","identifiers":["GHSA-cr6j-3jp9-rw65","CVE-2018-11776"],"repository_url":"https://github.com/hook-s3c/CVE-2018-11776-Python-PoC","blast_radius":0.0,"created_at":"2022-12-21T16:11:56.281Z","updated_at":"2026-08-15T20:14:45.881Z","epss_percentage":0.99991,"epss_percentile":0.99985,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNyNmotM2pwOS1ydzY1","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNyNmotM2pwOS1ydzY1","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.17","vulnerable_version_range":"\u003e= 2.5, \u003c= 2.5.16"},{"first_patched_version":"2.3.35","vulnerable_version_range":"\u003e= 2.0.4, \u003c= 2.3.34"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNyNmotM2pwOS1ydzY1/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo3N3EtMnFxZy02OTg5","url":"https://github.com/advisories/GHSA-j77q-2qqg-6989","title":"Apache Struts vulnerable to remote arbitrary command execution due to improper input validation","description":"Apache Struts versions prior to 2.3.32 and 2.5.10.1 contain incorrect exception handling and error-message generation during file-upload attempts using the Jakarta Multipart parser, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2018-10-18T19:24:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":10.0,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2017-5638","https://github.com/rapid7/metasploit-framework/issues/8064","https://cwiki.apache.org/confluence/display/WW/S2-045","https://cwiki.apache.org/confluence/display/WW/S2-046","https://exploit-db.com/exploits/41570","https://git1-us-west.apache.org/repos/asf?p=struts.git;a=commit;h=352306493971e7d5a756d61780d57a76eb1f519a","https://git1-us-west.apache.org/repos/asf?p=struts.git;a=commit;h=6b8272ce47160036ed120a48345d9aa884477228","https://github.com/advisories/GHSA-j77q-2qqg-6989","https://github.com/mazen160/struts-pwn","https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbgn03733en_us","https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbgn03749en_us","https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbhf03723en_us","https://isc.sans.edu/diary/22169","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922@%3Cannounce.apache.org%3E","https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html","https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt","https://struts.apache.org/docs/s2-045.html","https://struts.apache.org/docs/s2-046.html","https://support.lenovo.com/us/en/product_security/len-14200","https://twitter.com/theog150/status/841146956135124993","https://www.kb.cert.org/vuls/id/834067","https://www.symantec.com/security-center/network-protection-security-advisories/SA145","http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html","http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-002.txt","http://www.eweek.com/security/apache-struts-vulnerability-under-attack.html","http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html","https://github.com/apache/struts/commit/352306493971e7d5a756d61780d57a76eb1f519a","https://github.com/apache/struts/commit/b06dd50af2a3319dd896bf5c2f4972d2b772cf2b","https://web.archive.org/web/20170311203630/http://www.securityfocus.com/bid/96729","https://web.archive.org/web/20170921030226/http://www.securitytracker.com/id/1037973","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","https://security.netapp.com/advisory/ntap-20170310-0001","https://www.exploit-db.com/exploits/41614","https://www.imperva.com/blog/2017/03/cve-2017-5638-new-remote-code-execution-rce-vulnerability-in-apache-struts-2","https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites","https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=352306493971e7d5a756d61780d57a76eb1f519a","https://git1-us-west.apache.org/repos/asf?p=struts.git%3Ba=commit%3Bh=6b8272ce47160036ed120a48345d9aa884477228","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E","http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vulnerability-remote-code-execution","http://www.securityfocus.com/bid/96729","http://www.securitytracker.com/id/1037973","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5638"],"source_kind":"github","identifiers":["GHSA-j77q-2qqg-6989","CVE-2017-5638"],"repository_url":"https://github.com/rapid7/metasploit-framework","blast_radius":0.0,"created_at":"2022-12-21T16:12:59.366Z","updated_at":"2026-08-15T20:14:48.215Z","epss_percentage":0.99999,"epss_percentile":0.99993,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo3N3EtMnFxZy02OTg5","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo3N3EtMnFxZy02OTg5","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.10.1","vulnerable_version_range":"\u003e= 2.5.0, \u003c= 2.5.10"},{"first_patched_version":"2.3.32","vulnerable_version_range":"\u003e= 2.3.0, \u003c= 2.3.31"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo3N3EtMnFxZy02OTg5/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1eDctM3Y4NS13cGM0","url":"https://github.com/advisories/GHSA-x5x7-3v85-wpc4","title":"Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used","description":"In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.  NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2018-10-16T19:37:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2017-9804","https://security.netapp.com/advisory/ntap-20180629-0001/","https://struts.apache.org/docs/s2-050.html","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2","http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txt","http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","https://github.com/apache/struts/commit/418a20c0594f23764fe29ced400c1219239899a","https://web.archive.org/web/20171113165852/http://www.securityfocus.com/bid/100612","https://web.archive.org/web/20201021075553/http://www.securitytracker.com/id/1039261","https://github.com/advisories/GHSA-x5x7-3v85-wpc4"],"source_kind":"github","identifiers":["GHSA-x5x7-3v85-wpc4","CVE-2017-9804"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:13:35.595Z","updated_at":"2026-09-25T19:10:22.499Z","epss_percentage":0.08237,"epss_percentile":0.94642,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1eDctM3Y4NS13cGM0","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1eDctM3Y4NS13cGM0","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.34","vulnerable_version_range":"\u003e= 2.3.7, \u003c= 2.3.33"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1eDctM3Y4NS13cGM0/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThtcjUtaDI4Zy0zNnF4","url":"https://github.com/advisories/GHSA-8mr5-h28g-36qx","title":"Spring AOP functionality (Struts) vulnerable to DoS attack","description":"When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2018-10-16T19:37:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2017-9787","https://lists.apache.org/thread.html/3795c4dd46d9ec75f4a6eb9eca11c11edd3e796c6c1fd7b17b5dc50d@%3Cannouncements.struts.apache.org%3E","https://lists.apache.org/thread.html/de3d325f0433cd3b42258b6a302c0d7a72b69eedc1480ed561d3b065@%3Cannouncements.struts.apache.org%3E","https://security.netapp.com/advisory/ntap-20180706-0002/","http://struts.apache.org/docs/s2-049.html","http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","https://github.com/apache/struts/commit/086b63735527d4bb0c1dd0d86a7c0374b825ff2","https://github.com/apache/struts/commit/0d6442bab5b44d93c4c2e63c5335f0a331333b9","https://web.archive.org/web/20170910013819/http://www.securitytracker.com/id/1039115","https://web.archive.org/web/20200227144723/http://www.securityfocus.com/bid/99562","https://github.com/advisories/GHSA-8mr5-h28g-36qx"],"source_kind":"github","identifiers":["GHSA-8mr5-h28g-36qx","CVE-2017-9787"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:13:35.605Z","updated_at":"2026-09-24T15:11:19.307Z","epss_percentage":0.10554,"epss_percentile":0.95567,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThtcjUtaDI4Zy0zNnF4","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThtcjUtaDI4Zy0zNnF4","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.3.33","vulnerable_version_range":"\u003e= 2.3.7, \u003c 2.3.33"},{"first_patched_version":"2.5.12","vulnerable_version_range":"\u003e= 2.5.0, \u003c 2.5.12"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThtcjUtaDI4Zy0zNnF4/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlncDctanZtMi1yNG14","url":"https://github.com/advisories/GHSA-9gp7-jvm2-r4mx","title":"Apache Struts Improper Input Validation vulnerability","description":"If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2018-10-16T19:36:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.9,"cvss_vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2017-7672","https://lists.apache.org/thread.html/3795c4dd46d9ec75f4a6eb9eca11c11edd3e796c6c1fd7b17b5dc50d@%3Cannouncements.struts.apache.org%3E","https://security.netapp.com/advisory/ntap-20180706-0002/","http://struts.apache.org/docs/s2-047.html","http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","https://web.archive.org/web/20170907215142/http://www.securitytracker.com/id/1039114","https://web.archive.org/web/20200227144724/http://www.securityfocus.com/bid/99563","https://github.com/advisories/GHSA-9gp7-jvm2-r4mx"],"source_kind":"github","identifiers":["GHSA-9gp7-jvm2-r4mx","CVE-2017-7672"],"repository_url":null,"blast_radius":0.0,"created_at":"2022-12-21T16:13:35.614Z","updated_at":"2026-09-24T15:11:19.307Z","epss_percentage":0.09835,"epss_percentile":0.95338,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlncDctanZtMi1yNG14","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlncDctanZtMi1yNG14","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.12","vulnerable_version_range":"\u003e= 2.5.0, \u003c 2.5.12"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlncDctanZtMi1yNG14/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeDktNWh4OC1jcmht","url":"https://github.com/advisories/GHSA-8fx9-5hx8-crhm","title":"Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal","description":"In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2018-10-16T19:35:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2017-12611","https://kb.netapp.com/support/s/article/ka51A000000CgttQAC/NTAP-20170911-0001","https://struts.apache.org/docs/s2-053.html","http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txt","http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","https://github.com/apache/struts/commit/2306f5f7fad7f0157f216f34331238feb0539fa","https://github.com/apache/struts/commit/637ad1c3707266c33daabb18d7754e795e6681f","https://web.archive.org/web/20170923161654/http://www.securityfocus.com/bid/100829","https://github.com/advisories/GHSA-8fx9-5hx8-crhm"],"source_kind":"github","identifiers":["GHSA-8fx9-5hx8-crhm","CVE-2017-12611"],"repository_url":"https://github.com/apache/struts","blast_radius":0.0,"created_at":"2022-12-21T16:13:35.635Z","updated_at":"2026-09-25T19:10:22.500Z","epss_percentage":0.87123,"epss_percentile":0.99742,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeDktNWh4OC1jcmht","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeDktNWh4OC1jcmht","packages":[{"ecosystem":"maven","package_name":"org.apache.struts:struts2-core","versions":[{"first_patched_version":"2.5.11","vulnerable_version_range":"\u003e= 2.5.0, \u003c= 2.5.10.1"},{"first_patched_version":"2.3.34","vulnerable_version_range":"\u003e= 2.0.1, \u003c= 2.3.33"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeDktNWh4OC1jcmht/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/maven/org.apache.struts:struts2-core","docker_dependents_count":167,"docker_downloads_count":75679701,"usage_url":"https://repos.ecosyste.ms/usage/maven/org.apache.struts:struts2-core","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/maven/org.apache.struts:struts2-core/dependencies","status":null,"funding_links":[],"critical":true,"issue_metadata":{"last_synced_at":"2026-09-20T21:30:40.598Z","issues_count":7,"pull_requests_count":1222,"avg_time_to_close_issue":58657.57142857143,"avg_time_to_close_pull_request":775197.1452205882,"issues_closed_count":7,"pull_requests_closed_count":1088,"pull_request_authors_count":42,"issue_authors_count":5,"avg_comments_per_issue":0.7142857142857143,"avg_comments_per_pull_request":1.0785597381342062,"merged_pull_requests_count":895,"bot_issues_count":1,"bot_pull_requests_count":533,"past_year_issues_count":0,"past_year_pull_requests_count":162,"past_year_avg_time_to_close_issue":null,"past_year_avg_time_to_close_pull_request":285972.7938931298,"past_year_issues_closed_count":0,"past_year_pull_requests_closed_count":131,"past_year_pull_request_authors_count":9,"past_year_issue_authors_count":0,"past_year_avg_comments_per_issue":null,"past_year_avg_comments_per_pull_request":0.8209876543209876,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":62,"past_year_merged_pull_requests_count":124,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/apache%2Fstruts/issues","maintainers":[{"login":"lukaszlenart","count":421,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lukaszlenart"},{"login":"kusalk","count":169,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/kusalk"},{"login":"sdutry","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sdutry"},{"login":"hboutemy","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/hboutemy"},{"login":"leandrohstein","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/leandrohstein"}],"active_maintainers":[{"login":"lukaszlenart","count":92,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lukaszlenart"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/org.apache.struts:struts2-core/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/org.apache.struts:struts2-core/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/org.apache.struts:struts2-core/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/org.apache.struts:struts2-core/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/org.apache.struts:struts2-core/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/org.apache.struts:struts2-core/codemeta","maintainers":[]}