PT-2025-31399 · Apache · Apache Struts Extras
Ryan Murphy
·
Published
2025-07-30
·
Updated
2025-08-06
·
CVE-2025-54656
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Struts Extras versions prior to 2
Description
This issue involves improper output neutralization for logs in Apache Struts Extras. When using LookupDispatchAction, untrusted input may be printed to logs without filtering. This can lead to log output where part of the message appears as a separate log line, potentially confusing log consumers. The project is retired and will not receive a fix for this issue.
Recommendations
Users are recommended to find an alternative or restrict access to the instance to trusted users.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Struts Extras