Apache Struts 2 Config Browser Detected

medium Web App Scanning Plugin ID 112547

Synopsis

Apache Struts 2 Config Browser Detected

Description

Apache Struts 2 Config Browser Plugin is a module to help view Struts application’s configuration at runtime.

This plugin has been detected on the web application by the scanner. It may be possible for an attacker to view Apache Struts version, loaded configuration or accessible action URLs for example and then conduct further attacks.

Solution

Remove Apache Struts 2 Config Browser Plugin or restrict access.

See Also

https://cwiki.apache.org/confluence/display/WW/S2-043

https://struts.apache.org/plugins/config-browser/

Plugin Details

Severity: Medium

ID: 112547

Type: remote

Published: 2/13/2019

Updated: 2/25/2022

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 2.9

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information