CVE-2017-7672
Summary
| CVE | CVE-2017-7672 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-07-13 15:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
|
lists.apache.org |
|
| Oracle Security Alert CVE-2017-9805 |
CONFIRM |
www.oracle.com |
|
| July 2017 Apache Struts Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Apache Struts URLValidator Flaw Lets Remote Users Deny Service - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Apache Struts CVE-2017-7672 Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Patch, Vendor Advisory |
| S2-047 - Apache Struts 2 Documentation - Apache Software Foundation |
CONFIRM |
struts.apache.org |
Mitigation, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981163 Java (maven) Security Update for org.apache.struts:struts2-core (GHSA-9gp7-jvm2-r4mx)