Описание
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
Ссылки
- Vendor Advisory
- VDB EntryVendor Advisory
- Third Party Advisory
- Issue Tracking
- Vendor Advisory
- Vendor Advisory
- VDB EntryVendor Advisory
- Third Party Advisory
- Issue Tracking
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and ...
Apache Struts vulnerable to possible DoS attack when using URLValidator
Уязвимость программной платформы Apache Struts, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3
5 Medium
CVSS2