Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mr5-h28g-36qx

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Spring AOP functionality (Struts) vulnerable to DoS attack

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

Пакеты

Наименование

org.apache.struts:struts2-core

maven
Затронутые версииВерсия исправления

>= 2.3.7, < 2.3.33

2.3.33

Наименование

org.apache.struts:struts2-core

maven
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.12

2.5.12

EPSS

Процентиль: 94%
0.13883
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

CVSS3: 3.1
redhat
больше 8 лет назад

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

CVSS3: 7.5
nvd
больше 8 лет назад

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

CVSS3: 7.5
debian
больше 8 лет назад

When using a Spring AOP functionality to secure Struts actions it is p ...

EPSS

Процентиль: 94%
0.13883
Средний

7.5 High

CVSS3