First published: Mon Jun 20 2016(Updated: )
If an application allows enter na URL field in a form and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Affected versions: Struts 2.3.20 - Struts 2.3.28.1 and Struts 2.5 External References: <a href="https://struts.apache.org/docs/s2-041.html">https://struts.apache.org/docs/s2-041.html</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.struts:struts2-core | >=2.5.0<2.5.13 | 2.5.13 |
maven/org.apache.struts:struts2-core | >=2.3.20<2.3.29 | 2.3.29 |
=2.3.20 | ||
=2.3.20.1 | ||
=2.3.20.3 | ||
=2.3.24 | ||
=2.3.24.1 | ||
=2.3.24.3 | ||
=2.3.28 | ||
=2.3.28.1 | ||
=2.5 | ||
=2.5-beta1 | ||
=2.5-beta2 | ||
=2.5-beta3 | ||
Apache Struts | =2.3.20 | |
Apache Struts | =2.3.20.1 | |
Apache Struts | =2.3.20.3 | |
Apache Struts | =2.3.24 | |
Apache Struts | =2.3.24.1 | |
Apache Struts | =2.3.24.3 | |
Apache Struts | =2.3.28 | |
Apache Struts | =2.3.28.1 | |
Apache Struts | =2.5 | |
Apache Struts | =2.5-beta1 | |
Apache Struts | =2.5-beta2 | |
Apache Struts | =2.5-beta3 | |
redhat/Struts | <2.3.29 | 2.3.29 |
redhat/Struts | <2.5.13 | 2.5.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.