Lucene search

K
githubGitHub Advisory DatabaseGHSA-4G42-GQRG-4633
HistoryJun 14, 2023 - 9:30 a.m.

Apache Struts vulnerable to memory exhaustion

2023-06-1409:30:42
CWE-770
GitHub Advisory Database
github.com
36
apache struts
denial of service
memory exhaustion
vulnerability
multipart forms
upgrade
version 2.5.31
version 6.1.2.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.023 Low

EPSS

Percentile

89.7%

Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.

Upgrade to Struts 2.5.31 or 6.1.2.1 or greater

Affected configurations

Vulners
Node
org.apache.struts\struts2Matchcore
OR
org.apache.struts\struts2Matchcore

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.023 Low

EPSS

Percentile

89.7%