QID 980800
QID 980800: Java (maven) Security Update for org.apache.struts:struts2-core (GHSA-x5x7-3v85-wpc4)
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x5x7-3v85-wpc4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-x5x7-3v85-wpc4 -
github.com/advisories/GHSA-x5x7-3v85-wpc4
CVEs related to QID 980800
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x5x7-3v85-wpc4 | org.apache.struts:struts2-core |
|