CVE-2017-7672: Input Validation
Published Jul 13, 2017
·Updated
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
Affected Software
8 affected componentsFixes available
maven/org.apache.struts:struts2-core>=2.5.0<2.5.12
2.5.12
Apache struts=2.5
Apache struts=2.5.1
Apache struts=2.5.2
Apache struts=2.5.5
Apache struts=2.5.8
Apache struts=2.5.10
Apache struts=2.5.10.1
Remediation
Event History
Jul 13, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Oct 16, 2018
Advisory Published
07:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-7672?
CVE-2017-7672 is considered a critical vulnerability due to its potential to overload server processes during URL validation.
2
How do I fix CVE-2017-7672?
To fix CVE-2017-7672, you should upgrade to Apache Struts version 2.5.12 or later.
3
What software versions are affected by CVE-2017-7672?
CVE-2017-7672 affects Apache Struts versions from 2.5.0 to 2.5.10.1.
4
What type of vulnerability is CVE-2017-7672?
CVE-2017-7672 is a denial-of-service vulnerability that can be exploited through URL validation.
5
Is there a workaround for CVE-2017-7672?
There is no known workaround for CVE-2017-7672; upgrading to the latest version is the recommended solution.