{"api_version":"v1","generated_at":"2026-10-05T22:40:00+00:00","product":{"cve_count":6,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-apache-struts-78d83f407808","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/apache-struts","name":"Struts","next_cursor":null,"observations":[{"affected":"Apache Struts: Struts 2.0.0 - Struts 2.5.25","affected_versions_present":true,"cve_id":"CVE-2020-17530","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-17530","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:35:31.563Z","patch_url":"https://www.oracle.com/security-alerts/cpujan2021.html","primary_source":"","published":"2020-12-11T01:11:04.000Z"},{"affected":"2.3.1.2","affected_versions_present":true,"cve_id":"CVE-2011-3923","cve_url":"https://cve.blacktree.nl/cve/CVE-2011-3923","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-06T23:53:32.156Z","patch_url":"","primary_source":"","published":"2019-11-01T13:57:37.000Z"},{"affected":"Apache Struts: 2.3 to 2.3.34, 2.5 to 2.5.16","affected_versions_present":true,"cve_id":"CVE-2018-11776","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11776","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:45:48.386Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","primary_source":"","published":"2018-08-22T13:00:00.000Z"},{"affected":"Apache Struts: Apache Struts before 2.3.34 and 2.5.x before 2.5.13","affected_versions_present":true,"cve_id":"CVE-2017-9805","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-9805","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:55:34.589Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","primary_source":"","published":"2017-09-15T19:00:00.000Z"},{"affected":"Apache Struts: 2.3.x before 2.3.32, 2.5.x before 2.5.10.1","affected_versions_present":true,"cve_id":"CVE-2017-5638","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5638","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:55:46.106Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html","primary_source":"","published":"2017-03-11T02:11:00.000Z"},{"affected":"n/a","affected_versions_present":true,"cve_id":"CVE-2013-2251","cve_url":"https://cve.blacktree.nl/cve/CVE-2013-2251","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-22T00:05:41.250Z","patch_url":"http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","primary_source":"","published":"2013-07-18T01:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache"}}
