
Reproduction environment for CVE-2014-0094 (Struts2 ClassLoader manipulation) using Docker, Tomcat, and Java 7 for security verification and testing.
For verification.
Refer to https://piyolog.hatenadiary.jp/entry/20140417/1397750197,
reproduced. The classLoader is working, but the crucial log is percent-encoded, so it does not lead to RCE ><
Windows version also added (but only 7u191...).
This also doesn't work, so maybe Tomcat is the cause...?