Apache Struts2 is prone to a remote code execution vulnerability S2-045, affecting Struts 2.3.5-2.3.31 and Struts 2.5-2.5.10. A remote attacker could exploit this vulnerability by sending certain crafted HTTP request with mal-formed Content-Type value. A successful attack could execute arbitrary code on the target server with the privilege of the web server. |