Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8738

Опубликовано: 20 сент. 2017
Источник: debian
EPSS Низкий

Описание

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libstruts1.2-javaremovedpackage
libstruts1.2-javaend-of-lifewheezypackage

Примечания

  • https://struts.apache.org/docs/s2-044.html

EPSS

Процентиль: 69%
0.006
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS3: 5.9
nvd
больше 8 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS3: 5.9
github
больше 3 лет назад

Apache Struts vulnerable to possible DoS attack when using URLValidator

EPSS

Процентиль: 69%
0.006
Низкий