Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qwv-cwgj-c8rj

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation in Apache Struts

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

Пакеты

Наименование

struts:struts

maven
Затронутые версииВерсия исправления

< 1.2.9

1.2.9

EPSS

Процентиль: 94%
0.1367
Средний

7.5 High

CVSS3

Дефекты

CWE-20
CWE-749

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 19 лет назад

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

redhat
больше 19 лет назад

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

CVSS3: 7.5
nvd
больше 19 лет назад

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

CVSS3: 7.5
debian
больше 19 лет назад

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 wit ...

fstec
больше 19 лет назад

Уязвимость метода getMultipartRequestHandler программной платформы Apache Struts, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.1367
Средний

7.5 High

CVSS3

Дефекты

CWE-20
CWE-749