Severity: low

Affected versions:
- Apache Struts (org.apache.struts:struts2-json-plugin) 7.2.1

Description:
Exposure of data element to wrong session vulnerability in the JSON plugin
of Apache Struts. Per-response serialization state could be shared across
concurrent requests, allowing response content associated with one request
to become observable in another. Only the SMD / JSON-RPC handling of the
JSON interceptor is affected, which is not enabled by default; applications
using the json result type are not affected.

This issue affects Apache Struts: 7.2.1.

Users are recommended to upgrade to version 7.3.0, which fixes the issue.

Credit:
g0w6y (https://github.com/g0w6y) (finder)

References:
https://cwiki.apache.org/confluence/display/WW/S2-071
https://www.cve.org/CVERecord?id=CVE-2026-73632


On behalf of the Apache Struts project
Ɓukasz Lenart

Reply via email to