The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
Source: NVD ↗ · CISA KEV Catalog ↗