Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8738

Опубликовано: 20 сент. 2017
Источник: debian
EPSS Низкий

Описание

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libstruts1.2-javaremovedpackage
libstruts1.2-javaend-of-lifewheezypackage

Примечания

  • https://struts.apache.org/docs/s2-044.html

EPSS

Процентиль: 88%
0.03259
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 9 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS3: 5.9
nvd
почти 9 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS3: 5.9
github
больше 4 лет назад

Apache Struts vulnerable to possible DoS attack when using URLValidator

EPSS

Процентиль: 88%
0.03259
Низкий