Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when dynamic method invocation is enabled, allows remote attackers to execute arbitrary code via method: prefix (related to chained expressions).
View the template here CVE-2016-3081.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2016-3081