CVE-2017-7672

CVSS v3.0 5.9 (Medium)
59% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 3.85 % (92th)
3.85% Progress
Affected Products 1
Advisories 1

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.

Weaknesses
CWE-20
Improper Input Validation
Related CVEs
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2017-07-13 15:29:00
(7 years ago)
Updated Date
2023-11-07 02:50:14
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Struts 2.5 cpe:2.3:a:apache:struts:2.5
  Apache Struts 2.5.1 cpe:2.3:a:apache:struts:2.5.1
  Apache Struts 2.5.2 cpe:2.3:a:apache:struts:2.5.2
  Apache Struts 2.5.5 cpe:2.3:a:apache:struts:2.5.5
  Apache Struts 2.5.8 cpe:2.3:a:apache:struts:2.5.8
  Apache Struts 2.5.10 cpe:2.3:a:apache:struts:2.5.10
  Apache Struts 2.5.10.1 cpe:2.3:a:apache:struts:2.5.10.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...