Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68493

Опубликовано: 11 янв. 2026
Источник: redhat
CVSS3: 7.1

Описание

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

An XML processing flaw has been found in Apache Struts. Parsing of XML configuration in the XWork component does not validate XML in proper way and it's vulnerable to XML external entity (XXE) injection.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8javapackages-tools:201801/google-guiceNot affected
Red Hat Fuse 7struts2-coreWill not fix
Red Hat JBoss Enterprise Application Platform 8struts2-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packstruts2-coreNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-112
https://bugzilla.redhat.com/show_bug.cgi?id=2428559org.apache.struts: Apache Struts: Information disclosure and denial of service via missing XML validation

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
3 месяца назад

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

CVSS3: 8.1
debian
3 месяца назад

Missing XML Validation vulnerability in Apache Struts, Apache Struts. ...

CVSS3: 8.1
github
3 месяца назад

Apache Struts 2 is Missing XML Validation

CVSS3: 8.1
fstec
4 месяца назад

Уязвимость программной платформы Apache Struts, связанная с отсутствием проверки подлинности XML-документов, позволяющая нарушителю проводить XXE-атаки

7.1 High

CVSS3