{"id":"CVE-2012-1592","description":"A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.","cvssScore":8.8,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-434"],"resolved":"MITIGATION-CANDIDATE","published":"2019-12-05","lastModified":"2026-06-16","affectedProducts":[{"vendor":"apache","product":"struts","version":"2.0.0"}],"totalAffectedProducts":1,"references":[{"url":"https://access.redhat.com/security/cve/cve-2012-1592","source":"patch-hint","tags":["redhat-cve"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1592","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/struts","source":"osv","tags":["PACKAGE"]},{"url":"https://github.com/apache/struts/blob/master/core/src/main/resources/struts-default.xml#L39-L76","source":"osv","tags":["WEB"]},{"url":"https://issues.apache.org/jira/browse/WW-5055","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/r348ed455a140273c40b974f0615dee692f7c9b26c6de2118b4280ef2%40%3Cissues.struts.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/r348ed455a140273c40b974f0615dee692f7c9b26c6de2118b4280ef2@%3Cissues.struts.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/r593ebb2f4c95b064e6901fd273eff256c493db952bdb484395948ffc%40%3Cissues.struts.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/r593ebb2f4c95b064e6901fd273eff256c493db952bdb484395948ffc@%3Cissues.struts.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/r93c4e3f6cb138cd117c739714f07e47af547183ba099ba46be2b2a5b%40%3Cissues.struts.apache.org%3E","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"patch-hint","decidingReason":"A reference points at an upstream fix (redhat-cve tier): https://access.redhat.com/security/cve/cve-2012-1592. That makes this CVE a candidate for an ARMR patch rule — it is the kind of defect ARMR can address, and there is a fix to work from. No rule exists and none is scheduled: writing one means reading the linked change and finding a hook point ARMR can express it at, which may turn out not to exist.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.struts:struts2-core"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (redhat-cve tier): https://access.redhat.com/security/cve/cve-2012-1592","decisive":true},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"no-match","detail":"A KEV listing, a CISA verdict of active exploitation, or a reviewed exploit catalogue carries this CVE — somebody has published a working exploit, so it stays a candidate"}],"patchHintUrl":"https://access.redhat.com/security/cve/cve-2012-1592","patchHintTier":"redhat-cve","affectedProducts":[{"vendor":"apache","product":"struts","isKnown":true,"cpe":"cpe:2.3:a:apache:struts:2.0.0:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.apache.struts:struts2-core","introduced":"2.0","fixed":"2.5.22"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/37009","title":"Apache Struts 2.0 - 'XSLTResult.java' Arbitrary File Upload","date":"2012-03-23"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["exploit-db"],"firstPOCDate":"2012-03-23"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.2855,"percentile":0.98025},"ssvc":{"available":false},"patchHintUrl":"https://access.redhat.com/security/cve/cve-2012-1592","patchHintTier":"redhat-cve"}