CVE-2012-1592A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
CWE-434 · Unrestricted file upload
Working exploit published
A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| Exploit-DB | Apache Struts 2.0 - 'XSLTResult.java' Arbitrary File Upload | 2012-03-23 |
A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.
| Decided by | patch-hint : A reference pointing at the upstream fix: a commit, a PR, a Red Hat bug |
|---|---|
| Finding | A reference points at an upstream fix (redhat-cve tier): https://access.redhat.com/security/cve/cve-2012-1592. That makes this CVE a candidate for an ARMR patch rule — it is the kind of defect ARMR can address, and there is a fix to work from. No rule exists and none is scheduled: writing one means reading the linked change and finding a hook point ARMR can express it at, which may turn out not to exist. |
| Candidate fix | https://access.redhat.com/security/cve/cve-2012-1592 : a Red Hat CVE page: the weakest tier, pinning no commit, but its existence means Red Hat triaged and shipped the CVE |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 2.0 | 6.5 | no band published | AV:N/AC:L/Au:S/C:P/I:P/A:P |
NVD | Primary |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.apache.struts:struts2-core |
2.0 | 2.5.22 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | struts | generic | 2.0.0 |
| osv | org.apache.struts | struts2-core | generic | ≥ 2.0 and < 2.5.22 |
| Published | 2019-12-05 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-16 | NVD's own last-modified date for this record. |