7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7 High
AI Score
Confidence
High
0.003 Low
EPSS
Percentile
66.3%
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDirΒ even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fix this issue.
www.openwall.com/lists/oss-security/2023/12/09/1
github.com/apache/struts
github.com/apache/struts/commit/3292152f8c0a77ee4827beede82b6580478a2c2a
github.com/apache/struts/commit/4c044f12560e22e00520595412830f9582d6dac7
github.com/apache/struts/commit/bf54436869c264941dd192c752a4abfaa65d3711
lists.apache.org/thread/6wj530kh3ono8phr642y9sqkl67ys2ft
nvd.nist.gov/vuln/detail/CVE-2023-41835
www.openwall.com/lists/oss-security/2023/12/09/1
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7 High
AI Score
Confidence
High
0.003 Low
EPSS
Percentile
66.3%