Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-41835
HistoryDec 05, 2023 - 9:15 a.m.

Design/Logic Flaw

2023-12-0509:15:00
PRIOn knowledge base
www.prio-n.com
6
multipart request
struts
logic flaw
fix
security issue
upgrade

6.8 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.3%

When a Multipart request is performed but some of the fields exceed the maxStringLengthย  limit, the upload files will remain in struts.multipart.saveDirย  even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

6.8 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.3%