Lucene search

K
f5F5F5:K000136957
HistorySep 22, 2023 - 12:00 a.m.

K000136957 : Apache struts vulnerability CVE-2023-41835

2023-09-2200:00:00
my.f5.com
5
apache struts
cve-2023-41835
upload files
multipart request
security advisory

6.6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.3%

Security Advisory Description

When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue. (CVE-2023-41835)

Impact

There is no impact; F5 products are not affected by this vulnerability.

6.6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.3%