北京赛克艾威科技有限公司 2026-01-11
Parsing of XML configuration in XWork component does not validate XML in proper way and it's vulnerable to XML external entity \(XXE\) injection.
Upgrade to Struts 6.1.1 at least.
https://cwiki.apache.org/confluence/display/WW/S2-069