Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-383p-xqxx-rrmp

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Denial of service in Apache Struts

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

Пакеты

Наименование

org.apache.struts:struts2-core

maven
Затронутые версииВерсия исправления

>= 2.0.0, <= 2.3.24.1

2.3.24.3

Наименование

ognl:ognl

maven
Затронутые версииВерсия исправления

< 3.0.12

3.0.12

EPSS

Процентиль: 94%
0.08375
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 10 лет назад

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

redhat
около 10 лет назад

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

CVSS3: 5.3
nvd
около 10 лет назад

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

CVSS3: 5.3
debian
около 10 лет назад

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method re ...

EPSS

Процентиль: 94%
0.08375
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20