Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5012
HistorySep 05, 2017 - 9:13 p.m.

Regular Expression Denial Of Service (ReDoS)

2017-09-0521:13:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.039 Low

EPSS

Percentile

92.0%

struts2-core and xwork-core are vulnerable to regular expression denial of service (ReDoS) attacks. When the URLValidator is used it is possible to overload the server process through an attacker controlled URL. These attacks are as a result of an incomplete fix for CVE-2017-7672.