CVE-2009-1275
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (2.81%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.81% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- apache/tiles
- Source
- cve@mitre.org
References
- http://svn.apache.org/viewvc/tiles/framework/trunk/src/site/apt/security/security-bulletin-1.apt?revision=741913Vendor Advisory
- http://www.securityfocus.com/bid/34657
- https://issues.apache.org/struts/browse/TILES-351Vendor Advisory
- http://svn.apache.org/viewvc/tiles/framework/trunk/src/site/apt/security/security-bulletin-1.apt?revision=741913Vendor Advisory
- http://www.securityfocus.com/bid/34657
- https://issues.apache.org/struts/browse/TILES-351Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.