Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86vq-8qhc-5rqw

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Apache Struts vulnerable to possible DoS attack when using URLValidator

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

Пакеты

Наименование

org.apache.struts:struts2-core

maven
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.13

2.5.13

EPSS

Процентиль: 69%
0.006
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS3: 5.9
nvd
больше 8 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

CVSS3: 5.9
debian
больше 8 лет назад

In Apache Struts 2.5 through 2.5.5, if an application allows entering ...

EPSS

Процентиль: 69%
0.006
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20