Apache has patched a critical remote code-execution vulnerability in Struts 2, and users should update immediately. A critical remote code-execution vulnerability in Apache Struts 2, the popular ...
I'm no Struts expert, but my guess is that Struts adds a Servlet Mapping for anything in the context that ends in .xml.
Proof-of-Concept (PoC) code of an exploit to trigger two security vulnerabilities in the Apache Struts 2 web application framework is publicly available on internet. Last week, Apache published a ...