Maven package intelligence

org.apache.struts:struts2-rest-plugin Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.struts:struts2-rest-plugin, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting org.apache.struts:struts2-rest-plugin
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
org.apache.struts:struts2-rest-plugin KEV with sensor-observed exploitation activity

Review org.apache.struts:struts2-rest-plugin exploitation against the versions you run

All one exploited org.apache.struts:struts2-rest-plugin vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.apache.struts:struts2-rest-plugin vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for...

In CISA 03 Nov 2021

Recurring weakness patterns

Deserialization of Untrusted Data account for mapped occurrences across this org.apache.struts:struts2-rest-plugin KEV portfolio.

Browse all KEVs →