CVE-2016-4436: struts: Action name clean up is error prone

Severity: Critical

CVSS Score: 9.8

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.