CVE-2023-41835

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.26 % (66th)
0.26% Progress
Affected Products 1
Advisories 1

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Weaknesses
CWE-459
Incomplete Cleanup
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2023-12-05 09:15:07
(9 months ago)
Updated Date
2023-12-13 21:26:41
(9 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Struts from 2.0.0 version and prior 2.5.32 version cpe:2.3:a:apache:struts >= 2.0.0 < 2.5.32
  Apache Struts from 6.1.2.1 version and prior 6.3.0.1 version cpe:2.3:a:apache:struts >= 6.1.2.1 < 6.3.0.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...