https://seclists.org/oss-sec/2023/q4/265: CVE-2023-41835: Apache Struts: excessive disk usage
Published Dec 9, 2023
·Updated
Affected Software
2 affected components
Apache struts>=2.0.0<2.5.31
Apache struts>=6.1.2.1<6.3.0
Frequently Asked Questions
1
What is the severity of CVE-2023-41835?
CVE-2023-41835 has a moderate severity level.
2
Which versions of Apache Struts are affected by CVE-2023-41835?
CVE-2023-41835 affects Apache Struts versions from 2.0.0 to 2.5.31 and 6.1.2.1 to 6.3.0.
3
How do I fix CVE-2023-41835?
Fix CVE-2023-41835 by upgrading to the latest version of Apache Struts that is not affected by this vulnerability.
4
What issue does CVE-2023-41835 cause?
CVE-2023-41835 causes excessive disk usage due to upload files remaining in the specified save directory after Multipart requests fail.
5
What is the potential impact of CVE-2023-41835?
The potential impact of CVE-2023-41835 is that it can lead to significant disk space consumption on servers handling multipart file uploads.