CVE-2025-68493: Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.struts:struts2-coreto a version that resolves this vulnerability.Fixed in 6.1.1 - Upgrade
Upgrade
Apache Struts (XWork component)to a version that resolves this vulnerability.Fixed in 6.1.1Patch CVE-2025-68493
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68493?
CVE-2025-68493 is classified as a high-severity vulnerability due to its potential to allow attackers to exploit missing XML validation.
How do I fix CVE-2025-68493?
To fix CVE-2025-68493, upgrade Apache Struts to version 6.1.1 or later.
What versions are affected by CVE-2025-68493?
CVE-2025-68493 affects Apache Struts versions from 2.0.0 before 2.2.1 and from 2.2.1 through 6.1.0.
What are the risks associated with CVE-2025-68493?
The risks associated with CVE-2025-68493 include potential unauthorized access and manipulation of XML data in applications using affected versions of Apache Struts.
Is there a workaround for CVE-2025-68493 if I can't upgrade?
There are no recommended workarounds for CVE-2025-68493, and upgrading to a patched version is the only solution.