{"id":"CVE-2016-1182","details":"ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.","aliases":["GHSA-5ggr-mpgw-3mgx"],"modified":"2026-08-18T08:15:24.642367Z","published":"2016-07-04T22:59:02.880Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:apache:struts:1.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.0:beta1:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.0:beta2:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.0:beta3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.0-beta1"},{"last_affected":"1.0-beta1"},{"introduced":"1.0-beta1"},{"last_affected":"1.0-beta1"},{"introduced":"1.0-beta2"},{"last_affected":"1.0-beta2"},{"introduced":"1.0-beta2"},{"last_affected":"1.0-beta2"},{"introduced":"1.0-beta3"},{"last_affected":"1.0-beta3"},{"introduced":"1.0-beta3"},{"last_affected":"1.0-beta3"}],"source":"CPE_STRING","vendor_product":"apache:struts"}]},"references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"ADVISORY","url":"http://jvn.jp/en/jp/JVN65044642/index.html"},{"type":"ADVISORY","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2016-000097"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91067"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91787"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1036056"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2016-1182"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180629-0006/"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1343540"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"},{"type":"FIX","url":"https://github.com/kawasima/struts1-forever/commit/eda3a79907ed8fcb0387a0496d0cb14332f250e8"},{"type":"FIX","url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/struts1","events":[{"introduced":"2f31da8d6315acf6f8e9bf44250345d1d9363f85"},{"last_affected":"432ca08cb5f436f290ab3dcaa9267739cf8f6f89"}],"database_specific":{"cpe":["cpe:2.3:a:apache:struts:1.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.0.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.0.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.1:b1:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.1:b2:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.1:b3:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.1:rc1:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.1:rc2:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.5:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.7:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.8:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.3.5:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.3.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.3.7:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.3.8:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.3.9:*:*:*:*:*:*:*","cpe:2.3:a:apache:struts:1.3.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.0.1"},{"last_affected":"1.0.1"},{"introduced":"1.0.2"},{"last_affected":"1.0.2"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.1-b1"},{"last_affected":"1.1-b1"},{"introduced":"1.1-b2"},{"last_affected":"1.1-b2"},{"introduced":"1.1-b3"},{"last_affected":"1.1-b3"},{"introduced":"1.1-rc1"},{"last_affected":"1.1-rc1"},{"introduced":"1.1-rc2"},{"last_affected":"1.1-rc2"},{"introduced":"1.2.0"},{"last_affected":"1.2.0"},{"introduced":"1.2.1"},{"last_affected":"1.2.1"},{"introduced":"1.2.2"},{"last_affected":"1.2.2"},{"introduced":"1.2.3"},{"last_affected":"1.2.3"},{"introduced":"1.2.4"},{"last_affected":"1.2.4"},{"introduced":"1.2.5"},{"last_affected":"1.2.5"},{"introduced":"1.2.6"},{"last_affected":"1.2.6"},{"introduced":"1.2.7"},{"last_affected":"1.2.7"},{"introduced":"1.2.8"},{"last_affected":"1.2.8"},{"introduced":"1.2.9"},{"last_affected":"1.2.9"},{"introduced":"1.3.5"},{"last_affected":"1.3.5"},{"introduced":"1.3.6"},{"last_affected":"1.3.6"},{"introduced":"1.3.7"},{"last_affected":"1.3.7"},{"introduced":"1.3.8"},{"last_affected":"1.3.8"},{"introduced":"1.3.9"},{"last_affected":"1.3.9"},{"introduced":"1.3.10"},{"last_affected":"1.3.10"}],"source":"CPE_STRING"}}],"versions":["1.0","1.0.1","1.0.2","1.1","1.1-b1","1.1-b2","1.1-b3","1.1-rc1","1.1-rc2","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.10","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-1182.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/kawasima/struts1-forever","events":[{"introduced":"0"},{"fixed":"eda3a79907ed8fcb0387a0496d0cb14332f250e8"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-1182.json","vanir_signatures_modified":"2026-08-18T08:15:24Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/kawasima/struts1-forever/commit/eda3a79907ed8fcb0387a0496d0cb14332f250e8","target":{"file":"src/share/org/apache/struts/action/ActionServlet.java"},"deprecated":false,"digest":{"line_hashes":["105683631592247336656902944296599776314","40981726263095459424735472524808111251","2862303786404748042128178646467853349","207811457015275234257908205684295616493","277441258005566005519449599142878175700","312030805473486047810321879232524257574","282885639057810389179926927882785283503","204003968012705145478634013621690649237","304135678579568505631571992824951596339","243801532632016926960935286584807912263","217952086855472955496748280862806822199","305835152997505964804853882214061065472","229000502007580529303393046443959208742","30950044751233646112604525648435103748","259790258951861695249469713590068846770","233806469193145712396754822240236768822","135017837667307501811633680627790578472","257915629249777109357690232717200368499","72090433207419475626824692099586187379","99361996744071112323855774539141373025","149986068576086754127419569682222825213","136573233982601750858815088475377704808","78929048846053596461475036927463911723","258880862603859572277040310730946367789","308953546970365236756095253658591166631","78232233485352958434019412894233927009","48192962668982626538339483583244948777","64207166715813736093283923163539143977","276937143968145029020682005467026873783","83311304532829486008134214003320990549","230473023252087587097637910274006300896","309891649199857882751962721816820094800","77828087490743293410210199591691997086","253655484813366289844608959980497130922","163919496591251264925710851458967823163","207431811514667770692319474526457444558","96744140631647954610835818087371790242","127303369594388276279524254994130425455","203236370221193438834646047220884227858","263253822658907603002033271460854479663","58025557969618660640075213532826563098","244644852332381914097874412335171371959"],"threshold":0.9},"id":"CVE-2016-1182-764707ed","signature_type":"Line"},{"target":{"file":"src/share/org/apache/struts/action/ActionServlet.java","function":"initOther"},"deprecated":false,"digest":{"function_hash":"314656000574971036214094989453598472483","length":1210},"id":"CVE-2016-1182-9b3dfe6b","signature_type":"Function","signature_version":"v1","source":"https://github.com/kawasima/struts1-forever/commit/eda3a79907ed8fcb0387a0496d0cb14332f250e8"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}]}