CVE-2017-9804: Input Validation
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9804?
CVE-2017-9804 has a medium severity rating, which indicates it poses a significant risk to affected systems.
How do I fix CVE-2017-9804?
To fix CVE-2017-9804, update Apache Struts to version 2.5.13 or higher for 2.5.x series, or to version 2.3.34 or higher for 2.3.x series.
Which versions are affected by CVE-2017-9804?
CVE-2017-9804 affects Apache Struts versions 2.3.7 through 2.3.33 and 2.5 through 2.5.12.
What type of vulnerability is CVE-2017-9804?
CVE-2017-9804 is a denial-of-service vulnerability that can overload the server during URL validation.
How does CVE-2017-9804 impact applications?
CVE-2017-9804 can allow an attacker to craft a malicious URL that results in a denial of service for applications using vulnerable versions of Struts.