Apache Tiles Vulnerable to XSS via EL Expression Injection
Moderate severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 23, 2024
Package
Affected versions
>= 2.1, < 2.1.2
Patched versions
2.1.2
Description
Published by the National Vulnerability Database
Apr 9, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Jan 23, 2024
Reviewed
Jan 23, 2024
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1)
tiles:putAttribute
and (2)tiles:insertTemplate
JSP tags.References